Junglewise Threat Intelligence

CVE-2026-90244: Linux kernel IOMMU DMA race condition in MSI page list

CVE-2026-90244 · Severity: high · CVSS 7.8 · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A race condition exists in the Linux kernel's IOMMU DMA subsystem when handling MSI (Message Signaled Interrupt) pages. In virtual machine scenarios where multiple PCIe devices are assigned through VFIO's legacy container, concurrent MSI allocation from guest drivers can corrupt the shared MSI page list, leading to system instability, guest VM crashes, or potential privilege escalation within the VM.

Technical details

The vulnerability is a race condition in iommu_dma_get_msi_page() that fails to properly synchronize access to the shared msi_page_list structure. The issue arises because VFIO type1's legacy container merges multiple device groups into a single IOMMU domain when their properties match; however, the code only asserts per-group mutex locks via iommu_group_mutex_assert(), not domain-wide locking. On ARM SMMU and other IOMMU implementations that support IOMMU_RESV_SW_MSI, two guest devices can concurrently call into iommu_dma_get_msi_page() through different group mutexes while sharing the same domain, causing unsynchronized list corruption. The fix restores a static msi_prepare_lock that was previously removed in commit 288683c92b1a under the incorrect assumption that each domain is unique to a group. Attack vector requires guest VM access with assigned PCIe devices, making this primarily a guest-to-host or inter-VM denial of service vector.

Affected products

  • Linux Linux kernel affected versions include kernels from commit 288683c92b1a onwards until the fix is applied

Timeline

  • 2026-09-17: disclosed
  • 2026-09-17: patched: Fix committed restoring msi_prepare_lock

Related threats