Junglewise Threat Intelligence

CVE-2026-89446: Linux kernel iommufd resource leak on xa_store() failure

CVE-2026-89446 · Severity: info · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's iommufd subsystem (used for I/O Memory Management Unit virtualization) contains a resource leak when storing I/O address space (IOAS) objects into an internal data structure fails. If the store operation fails, a semaphore lock and object reference are not released, potentially causing system resource exhaustion or deadlocks over time. This is a subtle kernel-level memory management issue rather than a direct security exploit vector.

Technical details

The vulnerability is a resource leak in the iommufd_take_all_iova_rwsem() function in drivers/iommu/iommufd/ioas.c. The function acquires a write lock on ioas->iopt.iova_rwsem and increments an object reference count, then attempts to store the IOAS in a temporary xarray (ioas_list). If xa_store() fails and returns an error, the current IOAS's rwsem lock and reference count are not released before the function unwinds—only previously-stored entries in the xarray are cleaned up by iommufd_release_all_iova_rwsem(). The fix adds two lines to explicitly release the rwsem and decrement the refcount on xa_store() failure. No network attack vector; requires kernel code path execution. The vulnerability was introduced by commit 051ae5aa73d7 ("iommufd: Lock all IOAS objects") and fixed by commit 4ac2ce123824d5f885c868fa1f9f4d463141a2ba.

Affected products

  • Linux Linux kernel Linux 5.15+

Timeline

  • 2026-09-11: disclosed
  • 2026-08-10: patched: upstream commit 4ac2ce123824d5f885c868fa1f9f4d463141a2ba
  • 2026-09-07: patched: stable tree commit 07b4fe1367f076886c1c47a19c70936138325087

References

Related threats