Description
In the Linux kernel, the following vulnerability has been resolved:

iommu/dma: Check atomic pool allocation result directly

The non-blocking, non-coherent allocation path uses dma_alloc_from_pool(),
which returns the allocated page and fills cpu_addr only on success.

Do not rely on cpu_addr to detect allocation failure in this path. Check
the returned page directly before using it for the IOMMU mapping.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Update Kernel
AI Analysis

Impact

The Linux kernel’s IOMMU DMA allocation code can fault when the non‑blocking, non‑coherent path calls dma_alloc_from_pool(). The routine returns the allocated page only on success and sets cpu_addr accordingly, but the kernel mistakenly uses cpu_addr to detect failure. If cpu_addr is NULL and the returned page is NULL or invalid, the kernel may attempt an IOMMU mapping on an unreachable address, leading to a NULL pointer dereference and an OOPS or kernel panic, which in turn provides a denial of service. The weakness manifests as a classic null‑pointer dereference.

Affected Systems

The flaw resides in all Linux kernel builds that have not yet incorporated the patch found on the kernel git tree. Consequently, every system that runs a current Linux kernel and exercises the iommu/dma non‑blocking allocation path could be affected, including generic servers, embedded devices, and virtualized guests that rely on direct device access.

Risk and Exploitability

The vulnerability has a high CVSS score of 7.8. The EPSS score of less than 1% indicates a low current exploitation probability, and the flaw is not listed in the CISA KEV catalog. An attacker would need to trigger local kernel code execution or load a module that calls dma_alloc_from_pool without checking the returned page. If such an action is performed, the kernel may crash, which in turn results in denial of service. No evidence suggests this leads to privilege escalation.

Generated by OpenCVE AI on September 20, 2026 at 01:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel update that includes the iommu/dma allocation check fix.
  • If a kernel upgrade cannot be performed immediately, disable or restrict drivers that use the non‑blocking DMA allocation path or enforce stringent code review to validate returned pages before use.
  • Monitor system logs for IOMMU‑related PANIC or OOPS events and investigate anomalous failures promptly.

Generated by OpenCVE AI on September 20, 2026 at 01:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-346
CWE-476

Sun, 20 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Sat, 19 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iommu/dma: Check atomic pool allocation result directly The non-blocking, non-coherent allocation path uses dma_alloc_from_pool(), which returns the allocated page and fills cpu_addr only on success. Do not rely on cpu_addr to detect allocation failure in this path. Check the returned page directly before using it for the IOMMU mapping.
Title iommu/dma: Check atomic pool allocation result directly
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:02.646Z

Reserved: 2026-09-11T19:38:34.810Z

Link: CVE-2026-90388

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:38.287

Modified: 2026-09-18T18:17:56.770

Link: CVE-2026-90388

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:00:13Z

Weaknesses