Impact
The vulnerability occurs in the Linux kernel's iommu/vt-d subsystem. An out-of-scope memory access in domain_remove_dev_pasid triggers a general protection fault when a QEMU process is terminated, causing an oops that crashes the kernel. The fault results in a non‑canonical address read and can be exploited to bring down a system, providing a denial‑of‑service route from local or privileged attackers.
Affected Systems
The affected product is the Linux kernel. All kernel versions that lack the fix from commits 1e659db4…, 88397fad…, and a6dea58d… are impacted. The exact version range is not specified in the data, so any kernel prior to the patch should be considered at risk.
Risk and Exploitability
The CVSS score is not provided and the EPSS score is unavailable, so the baseline risk is uncertain. The issue does not appear in the CISA KEV catalog. Because the vulnerability requires interacting with the iommu/vt-d subsystem and typically requires privileged or local access to trigger the device removal path, the likelihood of exploitation by an external attacker is low. The risk is higher if a user can easily kill a QEMU instance or otherwise force device removal in an environment where a dummy domain is present.
OpenCVE Enrichment