Executive brief
The Linux kernel's Qualcomm MSM IOMMU driver has a resource cleanup bug during device initialization. If device registration fails, dangling list entries and uncleared sysfs objects remain in memory, potentially causing kernel crashes or use-after-free errors when the system later tries to access these stale references.
Technical details
The vulnerability exists in the msm_iommu_probe() function where an IOMMU device object is added to the global qcom_iommu_devices list before sysfs registration and core IOMMU registration. If iommu_device_sysfs_add() or iommu_device_register() fails, the function returns without unwinding the list insertion or sysfs entry. The driver core then releases the devm-managed memory, leaving a dangling list entry that subsequent list walks will dereference, causing a use-after-free condition. The fix adds explicit error paths to remove the sysfs device and delete the list entry in reverse order on failure, preventing the dangling references.
Affected products
- Linux Linux kernel linux kernel versions prior to patches 535a200220ca2c83bc8bf54bd2cbe045d6ee70c4 and 7f7074a886c4a93e3d12076ce60a510a1ebe400c
Timeline
- 2026-09-11: disclosed: CVE-2026-89452 published
- 2026-07-24: patched: Fix committed upstream (commit 535a200220ca2c83bc8bf54bd2cbe045d6ee70c4)
- 2026-09-07: patched: Fix backported to stable (commit 7f7074a886c4a93e3d12076ce60a510a1ebe400c)