Impact
The vulnerability is in the Linux kernel’s IOMMU VT‑d driver. When a device’s DMA alias is torn down, the kernel clears the context cache entry for the alias’s own requester ID but mistakenly constructs the invalidation using the device’s own requester ID. Consequently, cache entries for aliases other than the device’s own ID remain uncleared. These stale entries can still be used by the hardware after the associated PASID table has been freed, allowing the IOMMU to access freed memory. This use‑after‑free flaw (CWE‑416) can cause memory corruption, crashes, or data exposure. Based on the description, it is inferred that an attacker would need privileged control over device alias teardown operations to exploit this issue.
Affected Systems
All Linux kernel releases that compile the iommu/vt‑d implementation are affected. The advisory does not specify an exact kernel version range, so any kernel incorporating the referenced source code fragments is considered vulnerable until the fix is applied.
Risk and Exploitability
The CVSS score of 8.8 marks this as a high‑severity weakness. The EPSS score is below 1 %, indicating a low current probability of exploitation, and the vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector involves privileged manipulation of DMA alias teardown, typically requiring access to a device or a virtual machine that controls it. Successful exploitation could result in memory corruption or denial of service on the host.
OpenCVE Enrichment