Impact
The Linux kernel iommu/vt‑d code contains a reference‑counting flaw that prevents the IOPF (I/O Protection Filter) from being disabled when a domain is replaced at the RID level. The iopf_refcount therefore never decrements to zero, causing iopf_queue_remove_device() to never be called and triggering a WARN_ON during device release. This leak can accumulate over time, potentially exhausting internal queues or repeatedly generating warning messages, leading to system instability or a denial of service. The weakness is a reference‑counting error (CWE‑391).
Affected Systems
All Linux kernel builds that include the pre‑fix iommu/vt‑d implementation, regardless of the specific version number. The vulnerability was present before the commit that introduced the iopf_refcount fix. Any kernel that shipped the older code and has not yet applied the patch may be susceptible.
Risk and Exploitability
The EPSS score is reported as less than 1%, indicating a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The description shows that the flaw is triggered when a domain is replaced, a capability that typically requires kernel or root privileges. Based on this, it is inferred that the attack vector is local and requires elevated access, so the risk to unprivileged users is minimal.
OpenCVE Enrichment