Executive brief
A vulnerability in the Linux kernel's IOMMU file descriptor (iommufd) component could allow a local user to exhaust system memory. By requesting excessively large event queues, an attacker can deplete the kernel's atomic memory reserves, potentially leading to a system crash or denial of service. This affects systems using IOMMU virtualization features.
Technical details
A vulnerability in iommufd_viommu_report_event() within the Linux kernel stems from performing memory allocations (GFP_ATOMIC) inside a spinlock for virtual event queues (veventq). Because the depth of these queues is controlled by userspace, a local attacker can trigger numerous or large allocations that exhaust the kernel's atomic memory reserves. The fix moves the allocation outside the spinlock and switches to GFP_NOWAIT to prevent dipping into critical reserves. Patches have been merged into various stable branches including 6.18.x and 7.1.x.
Affected products
- Linux Linux 6.15 to 6.18.40, 7.1.4, 7.2-rc1
Timeline
- 2026-05-21: other: Initial fix authored
- 2026-07-25: disclosed: CVE published