Junglewise Threat Intelligence

CVE-2026-89445: Linux kernel iommufd use-after-free in selftest IOPF reporting

CVE-2026-89445 · Severity: high · CVSS 8.8 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's IOMMU subsystem contains a use-after-free vulnerability in its self-test code for handling I/O page faults. A race condition allows concurrent fault reporting to access freed memory, potentially causing kernel crashes or system instability. While this affects only test code rather than production IOMMU functionality, it can impact kernel development, testing, and debugging workflows.

Technical details

A use-after-free (UAF) vulnerability exists in the iommufd selftest TRIGGER_IOPF path. The selftest borrows an attach handle from group→pasid_array without synchronizing against concurrent PASID detach operations. When iommu_report_device_fault() runs concurrently, it can dereference a domain pointer after detach has freed the backing struct iommufd_attach_handle, leading to UAF. The fix adds an iopf_rwsem (read-write semaphore) to mock_dev to synchronize fault reporting (read-side) against attach/detach/replace operations (write-side). The semaphore is held across iommu_report_device_fault() calls and all domain manipulation paths, preventing dereference of freed handles. Attack vector is local (requires kernel-level access to trigger selftest) with no known wild exploitation.

Affected products

  • Linux Linux kernel Affected versions prior to patch commit 8c07df7cdfcf52f1ff276c588612aabc6c6b8399; patched in stable branches

Timeline

  • 2026-09-11: disclosed: CVE-2026-89445 published on NVD
  • 2026-08-13: patched: Fix committed upstream as 8c07df7cdfcf52f1ff276c588612aabc6c6b8399
  • 2026-09-07: patched: Backported to stable trees via cab2895729516799384d48560e6fca105fb3f927

References

Related threats