Executive brief
A vulnerability was identified in the Linux kernel's IOMMU (Input-Output Memory Management Unit) component, which manages how hardware devices access system memory. Under specific conditions involving device resets and concurrent memory domain changes, the system could experience a kernel crash or a 'use-after-free' error. This could lead to system instability or a complete service outage, impacting the availability of the affected server.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel's IOMMU subsystem within the `__iommu_group_set_domain_internal()` function. The root cause is an improper fencing mechanism where concurrent domain attachments are rejected during device recovery, even when the `IOMMU_SET_DOMAIN_MUST_SUCCEED` flag is present. This failure to update the `group->domain` pointer during teardown paths (like `__iommu_release_dma_ownership`) results in the pointer referencing a freed domain. When `pci_dev_reset_iommu_done()` subsequently attempts to re-attach the group domain, it accesses the freed memory. The fix involves honoring the 'must succeed' flag to ensure pointers are updated correctly and adding checks to prevent concurrent per-device detachment during recovery.
Affected products
- Linux Linux 7.0, 7.0.10, 7.1
Timeline
- 2026-04-24: other: Patch authored
- 2026-06-24: disclosed: CVE published