Description
In the Linux kernel, the following vulnerability has been resolved:

iommu/dma: Restore locking around msi_page_list

Unlike a group's default domain, which is always freshly allocated
and privately owned (iommu_group_alloc_default_domain()), VFIO type1's
legacy container merges any newly attached group into an existing
domain whenever their iommu_ops and cache-coherency enforcement match.

iommu_dma_get_msi_page() only asserts the caller's own group mutex is
held (iommu_group_mutex_assert()). On an IOMMU that publishes
IOMMU_RESV_SW_MSI, e.g. ARM SMMU, a VM with two such devices assigned
through the legacy container can have their guest drivers probe and
allocate MSIs in parallel; each host-side VFIO_DEVICE_SET_IRQS lands
on a different device fd and group mutex, but both devices' domains
are the same merged domain, so both can enter
iommu_dma_get_msi_page() concurrently and corrupt msi_page_list.

commit 288683c92b1a ("iommu: Make iommu_dma_prepare_msi() into a
generic operation") dropped the prior msi_prepare_lock on the
reasoning that "each iommu_domain is unique to a group," which holds
for default domains but not this VFIO type1 case. Restore the static
lock, since it's only guarding a corner case and will likely never
be contended.

iommufd avoids the equivalent problem by having its own callers
(iommufd_sw_map_msi()) take a ctx-wide sw_msi_lock before ever
reaching the shared list. VFIO type1 can't mirror that since it
dispatches to iommu_dma_sw_msi() which is outside VFIO's jurisdiction.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption potentially leading to privilege escalation
Action: Apply Patch Immediately
AI Analysis

Impact

The vulnerability arises when the Linux kernel fails to hold a lock around the shared msi_page_list during concurrent MSI page allocation by VFIO type1 devices. Two VMs that share the same IOMMU domain and have devices with IOMMU_RESV_SW_MSI support can allocate MSIs in parallel, entering iommu_dma_get_msi_page() simultaneously. Because the caller’s group mutex does not protect the msi_page_list in this scenario, the list can become corrupted, resulting in kernel memory corruption or a denial‑of‑service condition. The description does not explicitly state the exact exploit outcome, but the corruption of a kernel‑level data structure indicates that a privileged attacker might gain arbitrary kernel execution or compromise host stability.

Affected Systems

Affected systems are Linux kernel implementations that support VFIO type1 devices and the IOMMU_RESV_SW_MSI flag, such as those utilizing ARM SMMU or equivalent IOMMU hardware. No specific version range is listed in the data, so all kernel builds that expose this race condition prior to the patch are considered at risk.

Risk and Exploitability

The CVSS score of 7.8 classifies the vulnerability as high severity, and the EPSS score of less than 1% indicates a low probability of exploitation in the wild at present. The issue is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is local to a host that can run multiple VMs with shared IOMMU domains; an attacker with control over such VMs could trigger the race and corrupt the list, potentially leading to privilege escalation or a system crash. Because the flaw requires concurrent access, a successful exploit would likely require careful timing or multiple privileged VM instances.

Generated by OpenCVE AI on September 19, 2026 at 15:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the patch restoring the static lock around msi_page_list (the change referenced by commit 288683c92b1a).
  • If immediate kernel updates are unavailable, disable the VFIO type1 legacy container or avoid assigning multiple devices that share the same IOMMU domain to reduce concurrent access to the list.
  • Disable or remove the IOMMU_RESV_SW_MSI feature on affected devices or kernel modules if it is not required, to prevent the race condition from occurring.

Generated by OpenCVE AI on September 19, 2026 at 15:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iommu/dma: Restore locking around msi_page_list Unlike a group's default domain, which is always freshly allocated and privately owned (iommu_group_alloc_default_domain()), VFIO type1's legacy container merges any newly attached group into an existing domain whenever their iommu_ops and cache-coherency enforcement match. iommu_dma_get_msi_page() only asserts the caller's own group mutex is held (iommu_group_mutex_assert()). On an IOMMU that publishes IOMMU_RESV_SW_MSI, e.g. ARM SMMU, a VM with two such devices assigned through the legacy container can have their guest drivers probe and allocate MSIs in parallel; each host-side VFIO_DEVICE_SET_IRQS lands on a different device fd and group mutex, but both devices' domains are the same merged domain, so both can enter iommu_dma_get_msi_page() concurrently and corrupt msi_page_list. commit 288683c92b1a ("iommu: Make iommu_dma_prepare_msi() into a generic operation") dropped the prior msi_prepare_lock on the reasoning that "each iommu_domain is unique to a group," which holds for default domains but not this VFIO type1 case. Restore the static lock, since it's only guarding a corner case and will likely never be contended. iommufd avoids the equivalent problem by having its own callers (iommufd_sw_map_msi()) take a ctx-wide sw_msi_lock before ever reaching the shared list. VFIO type1 can't mirror that since it dispatches to iommu_dma_sw_msi() which is outside VFIO's jurisdiction.
Title iommu/dma: Restore locking around msi_page_list
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:08.500Z

Reserved: 2026-09-11T19:38:34.795Z

Link: CVE-2026-90244

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:20.400

Modified: 2026-09-18T18:17:50.720

Link: CVE-2026-90244

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:15:14Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')