Description
In the Linux kernel, the following vulnerability has been resolved:

iommu/sva: Set handle->dev before the SVA handle is visible

iommu_attach_device_pasid() installs the new SVA attach handle in the
group PASID lookup before iommu_sva_bind_device() returns. A concurrent
bind can therefore find and reuse the same handle after iommu_sva_lock is
dropped.

handle->dev was initialized after dropping iommu_sva_lock. This leaves a
window where a racing bind can return a handle whose dev pointer is still
NULL. A subsequent iommu_sva_unbind_device() can then dereference it via
handle->dev->iommu_group.

Initialize handle->dev before releasing iommu_sva_lock so any visible SVA
handle is fully initialized.
Published: 2026-09-11
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The flaw is a race condition in the Linux IOMMU SVA handler that allows a handle->dev pointer to remain NULL when a bind operation returns. When an unbind later dereferences that NULL pointer, the kernel crashes with a panic. This kernel crash results in a denial of service for the host system. The weakness corresponds to CWE‑476 – NULL Pointer Dereference.

Affected Systems

All Linux kernel releases that have not yet incorporated the commit moving handle->dev initialization above the iommu_sva_lock release are affected. The vendor list only mentions Linux and the affected component regardless of distribution.

Risk and Exploitability

The CVSS score of 4.1 indicates moderate severity, while the EPSS score of <1% points to a low exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. The race occurs between concurrent bind and unbind operations on the IOMMU SVA handle. Based on the description, it is inferred that such a race may require local or privileged privileges, but the CVE data does not explicitly state the required level of access.

Generated by OpenCVE AI on September 21, 2026 at 01:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the commit fixing this race condition; the patch guarantees that handle->dev is initialized before the IOMMU handle becomes visible.
  • If a kernel upgrade cannot be performed immediately, restrict IOMMU functionality to a single thread to prevent concurrent races; this mitigates the NULL dereference risk implied by CWE‑476.
  • Continuously monitor kernel log messages for OOPS, panic or malformed iommu_sva_unbind_device events and apply the kernel hotfix as soon as it becomes available.

Generated by OpenCVE AI on September 21, 2026 at 01:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iommu/sva: Set handle->dev before the SVA handle is visible iommu_attach_device_pasid() installs the new SVA attach handle in the group PASID lookup before iommu_sva_bind_device() returns. A concurrent bind can therefore find and reuse the same handle after iommu_sva_lock is dropped. handle->dev was initialized after dropping iommu_sva_lock. This leaves a window where a racing bind can return a handle whose dev pointer is still NULL. A subsequent iommu_sva_unbind_device() can then dereference it via handle->dev->iommu_group. Initialize handle->dev before releasing iommu_sva_lock so any visible SVA handle is fully initialized.
Title iommu/sva: Set handle->dev before the SVA handle is visible
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:43:16.730Z

Reserved: 2026-09-11T19:38:34.706Z

Link: CVE-2026-89451

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:25.727

Modified: 2026-09-11T20:19:25.727

Link: CVE-2026-89451

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:16Z

Links: CVE-2026-89451 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:30:08Z

Weaknesses