Description
In the Linux kernel, the following vulnerability has been resolved:

iommu/vt-d: Tear down scalable-mode context on probe failure

intel_pasid_setup_sm_context() walks a PCI device’s DMA aliases via
pci_for_each_dma_alias() and programs a scalable-mode context entry for
each RID. For a device with a dma_alias_mask, the callback is invoked
once for the device’s own RID and once for each alias bit, all with the
same pci_dev, so device_pasid_table_setup() runs for multiple RIDs.

pci_for_each_dma_alias() stops at the first callback error. Therefore, a
failure partway through the walk can leave context entries for already
processed RIDs present and still pointing to the device’s PASID table.

On this error path, intel_iommu_probe_device() currently jumps directly
to intel_pasid_free_table(), which frees the PASID table without
first tearing down those context entries. The IOMMU may then walk a
present context entry whose PASID table pointer references freed
memory.

intel_iommu_release_device() already performs teardown before freeing the
table. Apply the same ordering on the probe failure path.

device_pasid_table_teardown() safely handles RIDs that were never
programmed: iommu_context_addr() returns NULL when no context table has
been allocated, and clearing the Present bit of an already non-present
entry is a no-op. So unwind is safe for both the alias that failed and
any aliases not yet reached.
Published: 2026-09-17
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑free via IOMMU context entries
Action: Patch
AI Analysis

Impact

When an Intel IOMMU device is probed, a failure partway through the scalable‑mode context setup can leave RID entries that still point to a PASID table that has already been freed. Because the IOMMU may later access these stale entries, the kernel can dereference freed memory, leading to a use‑after‑free condition that could allow data leakage, corruption, or a kernel crash. This use‑after‑free vulnerability is the weakness underlying the problem.

Affected Systems

All Linux kernel releases that include the iommu/vt‑d code path and support Intel PASID allocation are affected. The issue manifests in any environment where a VTD device is probed during boot or hot‑plug, regardless of kernel version, until the fix is applied.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity risk. The EPSS score of <1% suggests that, although the vulnerability exists, the likelihood of exploitation is currently low, and the vulnerability is not listed the CISA KEV catalog. The most probable attack vector would be a kernel‑mode exploit that occurs during device probing or hot‑plug events, requiring the presence of an Intel IOMMU device and kernel support for scalable‑mode context allocation.

Generated by OpenCVE AI on September 20, 2026 at 02:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that incorporates the patch for CVE‑2026‑90241.
  • If an immediate update is not possible, disable IOMMU on systems that do not require passthrough or VT‑d functionality.
  • Configure system monitoring to alert on kernel panics or memory access errors associated with IOMMU devices, and investigate any abnormal activity.

Generated by OpenCVE AI on September 20, 2026 at 02:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Tear down scalable-mode context on probe failure intel_pasid_setup_sm_context() walks a PCI device’s DMA aliases via pci_for_each_dma_alias() and programs a scalable-mode context entry for each RID. For a device with a dma_alias_mask, the callback is invoked once for the device’s own RID and once for each alias bit, all with the same pci_dev, so device_pasid_table_setup() runs for multiple RIDs. pci_for_each_dma_alias() stops at the first callback error. Therefore, a failure partway through the walk can leave context entries for already processed RIDs present and still pointing to the device’s PASID table. On this error path, intel_iommu_probe_device() currently jumps directly to intel_pasid_free_table(), which frees the PASID table without first tearing down those context entries. The IOMMU may then walk a present context entry whose PASID table pointer references freed memory. intel_iommu_release_device() already performs teardown before freeing the table. Apply the same ordering on the probe failure path. device_pasid_table_teardown() safely handles RIDs that were never programmed: iommu_context_addr() returns NULL when no context table has been allocated, and clearing the Present bit of an already non-present entry is a no-op. So unwind is safe for both the alias that failed and any aliases not yet reached.
Title iommu/vt-d: Tear down scalable-mode context on probe failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:05.840Z

Reserved: 2026-09-11T19:38:34.795Z

Link: CVE-2026-90241

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:20.070

Modified: 2026-09-18T18:17:50.390

Link: CVE-2026-90241

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:45:18Z

Weaknesses

No weakness.