Description
In the Linux kernel, the following vulnerability has been resolved:

iommufd: Avoid locking internal accesses during unmap

iommufd_access_notify_unmap() skips internal accesses because they do
not have an external unmap callback to invoke.

However, the current test calls iommufd_lock_obj() before checking
whether the access is internal. If iommufd_lock_obj() succeeds, the loop
then sees the internal access and continues, bypassing the matching
iommufd_put_object() used by the normal unmap path. This leaks the
object reference taken by iommufd_lock_obj().

Check for internal accesses first so skipped entries are never locked.
Published: 2026-09-11
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Kernel reference counting leak
Action: Patch
AI Analysis

Impact

The flaw in the Linux kernel IOMMU daemon (iommufd) occurs during an unmap operation. If an internal access is encountered, the routine skips the normal unmap callback but still holds a lock on bypassed, the reference count for that object remains incremented. The net effect is a reference counting leak that can cause memory usage to grow beyond what a normal unmap would expend.

Affected Systems

All Linux kernel releases that do not include the commit that resolves the issue (0dbcdf4473a614adbd732d567c9b39ac0e040e0c). Any distribution shipping a kernel unchanged by this patch and that loads the iommufd module for IOMMU handling is affected.

Risk and Exploitability

The CVSS score of 4.4 indicates moderate severity. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, implying a very low probability of exploitation in the wild. The attack vector appears to require privileged kernel access to trigger the unmap of an internal IOMMU object, as the vulnerable code path is exercised only by kernel components. The exposed leak may lead to incremental resource consumption, but no direct denial‑of‑service or privilege‑escalation vector is documented.

Generated by OpenCVE AI on September 13, 2026 at 03:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update your Linux kernel to a release that incorporates commit 0dbcdf4473a614adbd732d567c9b39ac0e040e0c or later to close the reference count leak.
  • If a kernel upgrade is not possible, unload the iommufd module to prevent the vulnerable unmap logic from executing.
  • Observe system memory metrics and kernel logs for abnormal growth or frequent iommufd activity; apply general kernel hardening such as limiting local privilege escalation and patching other subsystems.

Generated by OpenCVE AI on September 13, 2026 at 03:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-911
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iommufd: Avoid locking internal accesses during unmap iommufd_access_notify_unmap() skips internal accesses because they do not have an external unmap callback to invoke. However, the current test calls iommufd_lock_obj() before checking whether the access is internal. If iommufd_lock_obj() succeeds, the loop then sees the internal access and continues, bypassing the matching iommufd_put_object() used by the normal unmap path. This leaks the object reference taken by iommufd_lock_obj(). Check for internal accesses first so skipped entries are never locked.
Title iommufd: Avoid locking internal accesses during unmap
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:43:14.094Z

Reserved: 2026-09-11T19:38:34.705Z

Link: CVE-2026-89447

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:25.227

Modified: 2026-09-11T20:19:25.227

Link: CVE-2026-89447

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:14Z

Links: CVE-2026-89447 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T03:30:17Z

Weaknesses
  • CWE-911

    Improper Update of Reference Count