Executive brief
A vulnerability was identified in the Linux kernel's IOMMU component, which manages how hardware devices access system memory. Under specific configurations, the system could fail to properly validate memory page sizes, potentially leading to unexpected behavior or system instability. This issue primarily affects system reliability and the secure isolation of hardware device memory access.
Technical details
A vulnerability in the Linux kernel iommupt driver stems from a missing check for PAGE_SIZE in the pgsize_bitmap within the map_range function. While technically allowed by some specifications, the absence of this check violates the expected design for iommu_domains used with the DMA API. An attacker or a misconfigured driver could trigger this condition, leading to a kernel warning (PT_WARN_ON) or improper fast-path execution during memory mapping. The fix involves lifting the warning into a conditional check to skip the fast path when PAGE_SIZE is missing from the bitmap. This issue is addressed in the generic_pt/iommu_pt.h component.
Affected products
- Linux Linux Kernel 6.19, 7.0.11
Timeline
- 2026-07-19: disclosed
- 2026-07-19: advisory