Description
In the Linux kernel, the following vulnerability has been resolved:

swiotlb: Preserve allocation virtual address for dynamic pools

swiotlb_alloc_tlb() can allocate from the DMA atomic pool when a decrypted
pool is needed from atomic context. With CONFIG_DMA_DIRECT_REMAP, the
atomic pool is backed by remapped virtual addresses, which are not the same
as the direct-map addresses returned by phys_to_virt().

swiotlb_init_io_tlb_pool() currently reconstructs the pool virtual address
from the physical start address. For atomic-pool backed allocations this
stores the wrong address in pool->vaddr. Later, swiotlb_free_tlb() passes
that address to dma_free_from_pool(), which will fail to recognize the
chunk

Pass the virtual address returned by the allocation path into
swiotlb_init_io_tlb_pool(), and store that address in pool->vaddr. This
keeps the pool free path using the same virtual address as the allocator.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel, the swiotlb allocator can allocate from the DMA atomic pool when a decrypted pool is needed from atomic context. With CONFIG_DMA_DIRECT_REMAP enabled, the atomic pool is backed by remapped virtual addresses that differ from the direct‑map addresses returned by phys_to_virt(). The initialization routine mistakenly reconstructs a virtual address from the physical start address, thereby storing an incorrect pool->vaddr. When freeing, swiotlb_free_tlb() passes this bogus address to dma_free_from_pool(), which fails to recognize the memory chunk. The result is a kernel memory leak or corruption that may exhaust kernel address space or corrupt critical kernel structures. This memory‑management flaw can lead to a denial‑of‑service condition.

Affected Systems

The flaw resides in the Linux kernel itself, affecting any kernel that includes the swiotlb allocator and uses the CONFIG_DMA_DIRECT_REMAP option. Specific kernel releases are not enumerated, so all builds that contain the buggy allocation path and enable the remapped pool configuration are potentially vulnerable. Users should check whether their kernel version contains the relevant swiotlb code and verify if the CONFIG_DMA_DIRECT_REMAP setting is active.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity. The EPSS score of less than 1% suggests that the likelihood of exploitation at present is very low, and the vulnerability is not listed in CISA's KEV catalog. The inference is that the attack vector is local: an attacker would need to exercise control over the kernel to trigger the allocation and deallocation sequences that invoke the flawed virtual‑address handling, typically via a local privilege escalation or kernel exploitation scenario.

Generated by OpenCVE AI on September 20, 2026 at 01:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the swiotlb virtual address fix
  • Reboot the system so the updated kernel is in use
  • If the system cannot be patched immediately, disable the CONFIG_DMA_DIRECT_REMAP configuration to prevent atomic pool allocations backed by remapped virtual addresses

Generated by OpenCVE AI on September 20, 2026 at 01:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sun, 20 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Sat, 19 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: swiotlb: Preserve allocation virtual address for dynamic pools swiotlb_alloc_tlb() can allocate from the DMA atomic pool when a decrypted pool is needed from atomic context. With CONFIG_DMA_DIRECT_REMAP, the atomic pool is backed by remapped virtual addresses, which are not the same as the direct-map addresses returned by phys_to_virt(). swiotlb_init_io_tlb_pool() currently reconstructs the pool virtual address from the physical start address. For atomic-pool backed allocations this stores the wrong address in pool->vaddr. Later, swiotlb_free_tlb() passes that address to dma_free_from_pool(), which will fail to recognize the chunk Pass the virtual address returned by the allocation path into swiotlb_init_io_tlb_pool(), and store that address in pool->vaddr. This keeps the pool free path using the same virtual address as the allocator.
Title swiotlb: Preserve allocation virtual address for dynamic pools
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:01.310Z

Reserved: 2026-09-11T19:38:34.809Z

Link: CVE-2026-90387

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:38.140

Modified: 2026-09-18T18:17:56.617

Link: CVE-2026-90387

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:45:17Z

Weaknesses