Impact
The flaw is a race condition in the Linux IOMMU SVA handler that allows a handle->dev pointer to remain NULL when a bind operation returns. When an unbind later dereferences that NULL pointer, the kernel crashes with a panic. This kernel crash results in a denial of service for the host system. The weakness corresponds to CWE‑476 – NULL Pointer Dereference.
Affected Systems
All Linux kernel releases that have not yet incorporated the commit moving handle->dev initialization above the iommu_sva_lock release are affected. The vendor list only mentions Linux and the affected component regardless of distribution.
Risk and Exploitability
The CVSS score of 4.1 indicates moderate severity, while the EPSS score of <1% points to a low exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. The race occurs between concurrent bind and unbind operations on the IOMMU SVA handle. Based on the description, it is inferred that such a race may require local or privileged privileges, but the CVE data does not explicitly state the required level of access.
OpenCVE Enrichment
Debian DSA