Description
In the Linux kernel, the following vulnerability has been resolved:

iommu/msm: Unwind probe state on registration failure

msm_iommu_probe() adds its devm-managed IOMMU object to
qcom_iommu_devices before adding the IOMMU sysfs device and registering
it with the IOMMU core.

If iommu_device_sysfs_add() fails, probe returns with the object still on
qcom_iommu_devices. The driver core then releases the devm allocation,
leaving a dangling list entry that later list walks may dereference.

If iommu_device_register() fails, the same dangling list entry remains
and the sysfs device is left registered as well.

Unwind the sysfs device and global list entry in reverse setup order on
the corresponding failure paths.
Published: 2026-09-11
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Crash (Denial of Service)
Action: Patch Now
AI Analysis

Impact

The Linux kernel's msm_iommu driver can leave a dangling list entry and a registered sysfs device when probe initialization fails. This flaw is a CWE-825 weakness that may result in a kernel panic or loss of kernel stability, effectively causing denial of service by crashing the system.

Affected Systems

All builds of the Linux kernel that include the msm_iommu driver are affected. No specific kernel version numbers are listed, so any kernel incorporating this driver is potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.4 signifies a high severity vulnerability, while the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that a local attacker could trigger this flaw by forcing a probe failure through a malformed device during kernel boot or by causing sysfs addition or IOMMU registration to fail, leading to a kernel crash. The attack vector is therefore likely local or confined to system boot time, rather than remote exploitation.

Generated by OpenCVE AI on September 21, 2026 at 01:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that unwinds the sysfs device and global list entry on failure; rebuild or upgrade the kernel to a patched version.
  • If an immediate kernel update cannot be applied, blacklist the msm_iommu module by adding a line to /etc/modprobe.d/blacklist.conf (for example, "blacklist msm_iommu") or removing the module from the initramfs so that the driver never loads and cannot leave dangling entries.
  • Optionally disable IOMMU support entirely via the kernel boot parameter iommu=off or by compiling the kernel without CONFIG_IOMMU_SUPPORT to further mitigate the risk in environments that still use the driver.

Generated by OpenCVE AI on September 21, 2026 at 01:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 11:15:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iommu/msm: Unwind probe state on registration failure msm_iommu_probe() adds its devm-managed IOMMU object to qcom_iommu_devices before adding the IOMMU sysfs device and registering it with the IOMMU core. If iommu_device_sysfs_add() fails, probe returns with the object still on qcom_iommu_devices. The driver core then releases the devm allocation, leaving a dangling list entry that later list walks may dereference. If iommu_device_register() fails, the same dangling list entry remains and the sysfs device is left registered as well. Unwind the sysfs device and global list entry in reverse setup order on the corresponding failure paths.
Title iommu/msm: Unwind probe state on registration failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-03T10:56:29.062Z

Reserved: 2026-09-11T19:38:34.706Z

Link: CVE-2026-89452

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:25.843

Modified: 2026-10-03T11:17:42.200

Link: CVE-2026-89452

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:17Z

Links: CVE-2026-89452 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:30:08Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference