Executive brief
The Linux kernel's Intel Analytics Accelerator (IAA) compression driver contains a bug in its decompression error handling that corrupts data when falling back to software decompression. When hardware decompression fails and the system is using SWIOTLB (Software I/O TLB, a DMA bounce buffer mechanism), stale cached data overwrites the correct decompression output, producing incorrect results. This can impact any system using IAA-accelerated decompression, particularly in virtualized or high-security environments where SWIOTLB is active.
Technical details
The vulnerability is a memory mapping lifecycle bug in the IAA decompression path. When a hardware analytics error occurs during decompress, the code attempts to fall back to the generic software deflate decompression while the destination buffer remains mapped for DMA with DMA_FROM_DEVICE direction. On systems using SWIOTLB, the subsequent dma_unmap_sg() operation copies stale bounce buffer data over the CPU-written output, corrupting the result. The fix unmaps both source and destination buffers before invoking the software fallback in the async path, and changes the sync path to return -EAGAIN to defer fallback until after unmapping. The vulnerability affects the IAA compression algorithm support added in commit 2ec6761df889.
Affected products
- Linux Linux kernel Affected versions from introduction of IAA support (circa 5.19+); patched in stable branches
Timeline
- 2026-09-11: disclosed
- 2026-08-15: patched: Initial fix in mainline kernel
- 2026-09-21: patched: Backported to stable kernel branches