Executive brief
The Linux kernel's iommufd subsystem (used for I/O Memory Management Unit virtualization) contains a resource leak when storing I/O address space (IOAS) objects into an internal data structure fails. If the store operation fails, a semaphore lock and object reference are not released, potentially causing system resource exhaustion or deadlocks over time. This is a subtle kernel-level memory management issue rather than a direct security exploit vector.
Technical details
The vulnerability is a resource leak in the iommufd_take_all_iova_rwsem() function in drivers/iommu/iommufd/ioas.c. The function acquires a write lock on ioas->iopt.iova_rwsem and increments an object reference count, then attempts to store the IOAS in a temporary xarray (ioas_list). If xa_store() fails and returns an error, the current IOAS's rwsem lock and reference count are not released before the function unwinds—only previously-stored entries in the xarray are cleaned up by iommufd_release_all_iova_rwsem(). The fix adds two lines to explicitly release the rwsem and decrement the refcount on xa_store() failure. No network attack vector; requires kernel code path execution. The vulnerability was introduced by commit 051ae5aa73d7 ("iommufd: Lock all IOAS objects") and fixed by commit 4ac2ce123824d5f885c868fa1f9f4d463141a2ba.
Affected products
- Linux Linux kernel Linux 5.15+
Timeline
- 2026-09-11: disclosed
- 2026-08-10: patched: upstream commit 4ac2ce123824d5f885c868fa1f9f4d463141a2ba
- 2026-09-07: patched: stable tree commit 07b4fe1367f076886c1c47a19c70936138325087