Description
In the Linux kernel, the following vulnerability has been resolved:

iommu/vt-d: Fix RB-tree corruption in probe error path

The info->node RB-tree member is zero-initialized via kzalloc. If
a device does not support ATS, the device_rbtree_insert() call is
skipped. If a subsequent probe step fails, the error path jumps to
device_rbtree_remove(), which misinterprets the zeroed node as
a tree root and corrupts the device RB-tree.

Fix this by explicitly initializing the RB-node as empty using
RB_CLEAR_NODE() during initialization and guarding the removal with
RB_EMPTY_NODE().
Published: 2026-08-15
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Linux kernel’s IOMMU/vt‑d subsystem misinitializes an RB‑tree node when a device does not support Address Translation Services (ATS). If a probe step then fails, the removal routine incorrectly treats the zeroed node as a tree root, corrupting the kernel’s RB‑tree structure. This corruption can overwrite kernel memory and may result in a denial‑of‑service, a crash, or, in the worst case, arbitrary code execution at kernel privileges. The weakness aligns with improper initialization and data structure corruption.

Affected Systems

All Linux kernel releases that contain the vt‑d code prior to the incorporation of the fix are affected. The specific affected kernel versions are not listed in the current data, but any kernel that includes the IOMMU/vt‑d module before the patched commit is susceptible. Vendors listed in the CNA data are generic Linux distributions that ship the upstream kernel.

Risk and Exploitability

With a CVSS score of 8.2, the vulnerability is classified as high severity. The EPSS score of < 1% indicates a very low likelihood that the weakness will be actively exploited in the wild at present. It is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation would likely require a local or privileged execution environment that can trigger a probe failure on a PCIe device lacking ATS support, activating the corrupted removal path. No public exploits have been reported, but the potential impact justifies prompt remediation.

Generated by OpenCVE AI on August 21, 2026 at 23:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that includes the patches which correctly initialize the RB node and guard removal, such as the kernel commits referenced in the advisory.
  • Reboot the system after updating so the new kernel is active.
  • If a kernel upgrade cannot be performed immediately, disable IOMMU/vt‑d usage for the affected devices by setting appropriate kernel parameters or by compiling the driver with the feature turned off to prevent the vulnerable probe path from executing.

Generated by OpenCVE AI on August 21, 2026 at 23:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-824
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 17 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Mon, 17 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Sat, 15 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Sat, 15 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix RB-tree corruption in probe error path The info->node RB-tree member is zero-initialized via kzalloc. If a device does not support ATS, the device_rbtree_insert() call is skipped. If a subsequent probe step fails, the error path jumps to device_rbtree_remove(), which misinterprets the zeroed node as a tree root and corrupts the device RB-tree. Fix this by explicitly initializing the RB-node as empty using RB_CLEAR_NODE() during initialization and guarding the removal with RB_EMPTY_NODE().
Title iommu/vt-d: Fix RB-tree corruption in probe error path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:46:16.092Z

Reserved: 2026-08-15T05:44:03.887Z

Link: CVE-2026-74355

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:36.887

Modified: 2026-08-17T06:19:30.180

Link: CVE-2026-74355

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-74355 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T00:00:16Z

Weaknesses
  • CWE-665

    Improper Initialization

  • CWE-824

    Access of Uninitialized Pointer