Description
In the Linux kernel, the following vulnerability has been resolved:

iommufd: Fix UAF in selftest IOPF reporting

IOMMUFD selftest TRIGGER_IOPF borrows an attach handle from
group->pasid_array without synchronizing against PASID detach,
then a concurrent iommu_report_device_fault() can dereference
that borrowed handle's domain pointer after the detach erases
the handle and frees the backing struct iommufd_attach_handle.
TRIGGER_IOPF then dereferences the freed handle, causing a UAF.

Fix by adding a iopf_rwsem in mock_dev to follow the expected design
of a real driver. Hold its read side across the whole
iommu_report_device_fault() call, and its write side around every
path that attaches, detaches, or replaces a device domain.
This can block new reports and drains in-flight reports before an old
attach handle or the IOPF fault parameter can be removed.
Also take the write side while registering a mock device, since
it can invoke the mock driver's default-domain attach callback.
Published: 2026-09-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Update Kernel
AI Analysis

Impact

In the LinuxOMMUFD selftest TRIGGER_IOPF routine. It occurs when an attach handle is borrowed from a PASID array without proper synchronization and a concurrent iommu_report_device_fault() call frees the handle. The selftest then dereferences the freed handle, causing a use‑after‑free that can crash the kernel. The CVE data does not describe any additional impact such as data disclosure or privilege escalation. The primary consequence is a loss of system stability as the kernel reboots or stops responding.

Affected Systems

This vulnerability affects Linux kernel builds that include the IOMMUFD selftest and lack the added iopf_rwsem synchronization introduced by the patch. No specific kernel versions are enumerated in the CVE data; any kernel prior to the commit that added the lock may be impacted. The impact is on all Linux distributions that ship an affected kernel version.

Risk and Exploitability

The CVSS score of 8.8 signifies a high severity of the flaw. The EPSS score of less than 1% indicates a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need local or privileged access to trigger the selftest and fault reporting. The likely attack vector is an operation that enables the IOMMUFD selftest or causes a concurrent fault report while the handle is borrowed, leading to a kernel crash. No direct path for escalation or data theft is documented. The overall risk is therefore a high‑severity denial‑of‑service with low exploitation likelihood under normal conditions.

Generated by OpenCVE AI on September 21, 2026 at 01:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel version that includes the commit adding the iopf_rwsem lock to prevent the use‑after‑free
  • If a newer kernel cannot be applied immediately, disable the IOMMUFD selftest by setting CONFIG_IOMMUFD_SELFTEST=n in the kernel configuration
  • After applying the change, monitor system logs such as dmesg or journalctl for kernel panics or crash events to confirm that the issue is mitigated

Generated by OpenCVE AI on September 21, 2026 at 01:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 11:15:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix UAF in selftest IOPF reporting IOMMUFD selftest TRIGGER_IOPF borrows an attach handle from group->pasid_array without synchronizing against PASID detach, then a concurrent iommu_report_device_fault() can dereference that borrowed handle's domain pointer after the detach erases the handle and frees the backing struct iommufd_attach_handle. TRIGGER_IOPF then dereferences the freed handle, causing a UAF. Fix by adding a iopf_rwsem in mock_dev to follow the expected design of a real driver. Hold its read side across the whole iommu_report_device_fault() call, and its write side around every path that attaches, detaches, or replaces a device domain. This can block new reports and drains in-flight reports before an old attach handle or the IOPF fault parameter can be removed. Also take the write side while registering a mock device, since it can invoke the mock driver's default-domain attach callback.
Title iommufd: Fix UAF in selftest IOPF reporting
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-03T10:56:27.940Z

Reserved: 2026-09-11T19:38:34.704Z

Link: CVE-2026-89445

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:24.990

Modified: 2026-10-03T11:17:42.070

Link: CVE-2026-89445

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:12Z

Links: CVE-2026-89445 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:30:08Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference