Executive brief
A vulnerability in the Linux kernel's memory management system can cause system instability or crashes when using certain external storage devices, such as Thunderbolt NVMe drives. This occurs when the system attempts to process oddly aligned data buffers, leading to internal memory mapping errors. While primarily a stability issue, it could potentially be used to disrupt system operations or cause a denial of service.
Technical details
A vulnerability in `iommu_dma_iova_link_swiotlb()` occurs when processing unaligned mappings. If the 'middle' section of a three-part mapping (head, middle, trailer) is empty due to a lack of aligned pages, the function calls `iommu_map()` with a size of 0. This is treated as an illegal operation, triggering an error unwind process that starts from an incorrect offset. This results in mapping corruption and subsequent `WARN_ON` triggers during destruction. The issue is frequently hit by NVMe passthrough commands (e.g., from smartctl) using unaligned buffers on systems with forced SWIOTLB. Patches have been released for various stable kernel branches to check for zero length before mapping and to use the correct offset during unlinking.
Affected products
- Linux Linux Kernel 6.16 to 6.18.35, 7.0 to 7.0.12
Timeline
- 2026-06-08: other: Patch authored
- 2026-06-25: advisory: CVE published