Impact
In the LinuxOMMUFD selftest TRIGGER_IOPF routine. It occurs when an attach handle is borrowed from a PASID array without proper synchronization and a concurrent iommu_report_device_fault() call frees the handle. The selftest then dereferences the freed handle, causing a use‑after‑free that can crash the kernel. The CVE data does not describe any additional impact such as data disclosure or privilege escalation. The primary consequence is a loss of system stability as the kernel reboots or stops responding.
Affected Systems
This vulnerability affects Linux kernel builds that include the IOMMUFD selftest and lack the added iopf_rwsem synchronization introduced by the patch. No specific kernel versions are enumerated in the CVE data; any kernel prior to the commit that added the lock may be impacted. The impact is on all Linux distributions that ship an affected kernel version.
Risk and Exploitability
The CVSS score of 8.8 signifies a high severity of the flaw. The EPSS score of less than 1% indicates a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need local or privileged access to trigger the selftest and fault reporting. The likely attack vector is an operation that enables the IOMMUFD selftest or causes a concurrent fault report while the handle is borrowed, leading to a kernel crash. No direct path for escalation or data theft is documented. The overall risk is therefore a high‑severity denial‑of‑service with low exploitation likelihood under normal conditions.
OpenCVE Enrichment