Description
In the Linux kernel, the following vulnerability has been resolved:

iommufd: Release current IOAS on xa_store() failure

iommufd_take_all_iova_rwsem() takes an object reference and the
iova_rwsem write lock before storing the IOAS in the temporary ioas_list
xarray.

If xa_store() fails, the current IOAS has not been inserted into
ioas_list yet. iommufd_release_all_iova_rwsem() only unwinds IOAS
objects already present in that xarray, so it cannot release the current
IOAS.

Release the current IOAS rwsem and object reference before unwinding the
previously stored entries.
Published: 2026-09-11
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Resource leak and potential kernel instability
Action: Apply Patch
AI Analysis

Impact

The_i the IOAS reference and its write lock when an xa_store() operation does not succeed. Because the current IOAS remains locked and an object reference is left unresolved, the bug results in a resource leak that can lead to device I/O failures or kernel instability over time. The flaw represents a CWE-772 missing release of a resource after acquisition.

Affected Systems

This issue resides in the generic iommufd driver that is part of the mainline Linux kernel. It potentially affects all Linux distributions that ship the default Linux kernel with this module enabled, unless a later kernel release back‑ports the fix. No specific version range is defined in the advisory, so all kernel versions before the patch are vulnerable. This inference is based on the vendor list and the description.

Risk and Exploitability

The CVSS score of 4.4 indicates moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV, implying no widespread exploitation has been reported. The likely attack vector is inferred from the kernel nature of the bug and would require a local attacker capable of executing privileged code or an attacker who can trigger a kernel failure that leaves the lock unreleased. Such an event would lead to a resource leak and possible deadlock, degrading system performance or causing kernel instability, but it does not enable remote code execution or direct data disclosure.

Generated by OpenCVE AI on September 21, 2026 at 01:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update your Linux kernel to the most recent patched release that corrects the iommufd release logic.
  • If an immediate kernel update is not possible, disable the problematic IOMMU functionality or the iommufd module on systems that can tolerate reduced I/O virtualization, or apply a temporary kernel configuration patch to release the IOAS lock on failure.
  • Continuously monitor /var/log/kern.log or dmesg output for IOMMU‑related errors and reboot or restart affected services if instability is detected.

Generated by OpenCVE AI on September 21, 2026 at 01:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iommufd: Release current IOAS on xa_store() failure iommufd_take_all_iova_rwsem() takes an object reference and the iova_rwsem write lock before storing the IOAS in the temporary ioas_list xarray. If xa_store() fails, the current IOAS has not been inserted into ioas_list yet. iommufd_release_all_iova_rwsem() only unwinds IOAS objects already present in that xarray, so it cannot release the current IOAS. Release the current IOAS rwsem and object reference before unwinding the previously stored entries.
Title iommufd: Release current IOAS on xa_store() failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:43:13.431Z

Reserved: 2026-09-11T19:38:34.704Z

Link: CVE-2026-89446

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:25.110

Modified: 2026-09-11T20:19:25.110

Link: CVE-2026-89446

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:13Z

Links: CVE-2026-89446 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:30:08Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime