Impact
A flaw in Linux kernel VT‑d handling causes a partially torn IOMMU context entry to remain marked present while its fields are being cleared, allowing the hardware to read an incomplete entry and produce unpredictable device behavior or spurious faults. The race arises because the kernel zeroes a 128‑bit context entry while the Present bit stays set and performs IOTLB invalidation without flushing, enabling the hardware to observe a half‑cleared entry in the context table. This race condition maps to CWE‑362 (Race Condition).
Affected Systems
Linux kernel – any version prior to the commit that enforces the proper sequence of clearing the Present bit, flushing the entry to the IOMMU, performing invalidations, and then zeroing the remaining fields. The affected builds are all distributions that ship the unpatched kernel and rely on VT‑d IOMMU support for device passthrough or isolation.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. The EPSS score is below 1 %, implying a low likelihood of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local with elevated privileges, as attacking the context teardown would require triggering a device unplug or driver unload, which requires local privileged access; this inference is based on the description. Nonetheless, the potential for hardware‑level faults justifies timely mitigation.
OpenCVE Enrichment
Debian DLA
Debian DSA