Executive brief
A vulnerability in the Linux kernel's Intel IOMMU driver can cause a system crash (kernel oops) when certain virtualization processes, such as QEMU, are terminated. This occurs because the system incorrectly attempts to access memory associated with a 'blocked' domain that does not exist. While primarily impacting system stability and availability, it could potentially be used to disrupt services on a host machine.
Technical details
The vulnerability is a NULL pointer dereference or out-of-bounds access (kernel oops) within the Intel VT-d implementation (drivers/iommu/intel/iommu.c). Specifically, the function 'domain_remove_dev_pasid' fails to account for the 'blocked' domain type, which is a dummy domain lacking a corresponding 'dmar_domain' structure. When a process like QEMU is killed, the kernel attempts to perform a PASID removal on this blocked domain, leading to a general protection fault. The fix involves adding a check to return early if the domain type is IOMMU_DOMAIN_BLOCKED, similar to how identity domains are handled. Patches have been backported to various stable branches including 6.18.x and 7.0.x.
Affected products
- Linux Linux 6.6 to 7.1
Timeline
- 2026-06-24: disclosed
- 2026-05-23: patched
- 2026-06-24: advisory