Impact
The kernel does not request Access Control Services (ACS) when T‑Boot forces IOMMU on, allowing a configuration where ACS is disabled but IOMMU is still enabled. This mis‑configuration can create scenarios where the IOMMU lacks proper access restrictions, potentially allowing incorrect device memory accesses or elevated privileges. The vulnerability is a failure to enforce required security controls rather than an active code execution flaw.
Affected Systems
All Linux kernel deployments that have not yet incorporated the recent patch, regardless of distribution, are affected. No specific version range is listed, so any older kernel that lacks the fix is at risk.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, implying no known exploitation evidence. The exploitability hinges on a configuration error the risk is considered moderate. Nevertheless, applying the patch removes the configuration gap and is recommended to prevent potential privilege escalation scenarios.
OpenCVE Enrichment