Impact
When an Intel IOMMU device is probed, a failure partway through the scalable‑mode context setup can leave RID entries that still point to a PASID table that has already been freed. Because the IOMMU may later access these stale entries, the kernel can dereference freed memory, leading to a use‑after‑free condition that could allow data leakage, corruption, or a kernel crash. This use‑after‑free vulnerability is the weakness underlying the problem.
Affected Systems
All Linux kernel releases that include the iommu/vt‑d code path and support Intel PASID allocation are affected. The issue manifests in any environment where a VTD device is probed during boot or hot‑plug, regardless of kernel version, until the fix is applied.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity risk. The EPSS score of <1% suggests that, although the vulnerability exists, the likelihood of exploitation is currently low, and the vulnerability is not listed the CISA KEV catalog. The most probable attack vector would be a kernel‑mode exploit that occurs during device probing or hot‑plug events, requiring the presence of an Intel IOMMU device and kernel support for scalable‑mode context allocation.
OpenCVE Enrichment
Debian DLA
Debian DSA