Impact
The vulnerability arises when the Linux kernel fails to hold a lock around the shared msi_page_list during concurrent MSI page allocation by VFIO type1 devices. Two VMs that share the same IOMMU domain and have devices with IOMMU_RESV_SW_MSI support can allocate MSIs in parallel, entering iommu_dma_get_msi_page() simultaneously. Because the caller’s group mutex does not protect the msi_page_list in this scenario, the list can become corrupted, resulting in kernel memory corruption or a denial‑of‑service condition. The description does not explicitly state the exact exploit outcome, but the corruption of a kernel‑level data structure indicates that a privileged attacker might gain arbitrary kernel execution or compromise host stability.
Affected Systems
Affected systems are Linux kernel implementations that support VFIO type1 devices and the IOMMU_RESV_SW_MSI flag, such as those utilizing ARM SMMU or equivalent IOMMU hardware. No specific version range is listed in the data, so all kernel builds that expose this race condition prior to the patch are considered at risk.
Risk and Exploitability
The CVSS score of 7.8 classifies the vulnerability as high severity, and the EPSS score of less than 1% indicates a low probability of exploitation in the wild at present. The issue is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is local to a host that can run multiple VMs with shared IOMMU domains; an attacker with control over such VMs could trigger the race and corrupt the list, potentially leading to privilege escalation or a system crash. Because the flaw requires concurrent access, a successful exploit would likely require careful timing or multiple privileged VM instances.
OpenCVE Enrichment