Impact
The kernel’s detect_intel_iommu() routine does not request Access Control Services when T‑Boot forces IOMMU. This omission means the IOMMU can be enabled while ACS remains disabled, allowing devices to map and potentially read or write memory outside their intended zones. The flaw is a missing enforcement of memory‑access control that could lead to unauthorized memory exposure.
Affected Systems
Any Linux kernel built before the commit that adds the tboot check in detect_intel_iommu() is affected. The vulnerability applies to all distributions that ship such kernel versions, as the defect resides in the open‑source Linux kernel itself. Vendors have not yet tagged a specific version in the provided data, so all earlier releases are potentially vulnerable.
Risk and Exploitability
The CVSS score of 9.3 marks the defect as critical, but the EPSS score of less than 1% suggests a very low current exploitation likelihood. The flaw is not listed in CISA KEV. Based on the description, the attack vector is inferred to be local or during boot on systems that use Intel’s T‑Boot for trusted execution, as the vulnerability is tied to T‑Boot forcing IOMMU. An attacker who can influence the boot environment or gain local access could exploit the missing ACS enforcement to bypass memory isolation safeguards.
OpenCVE Enrichment
Debian DSA