CVE-2026-89447
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
iommufd: Avoid locking internal accesses during unmap
iommufd_access_notify_unmap() skips internal accesses because they do not have an external unmap callback to invoke.
However, the current test calls iommufd_lock_obj() before checking whether the access is internal. If iommufd_lock_obj() succeeds, the loop then sees the internal access and continues, bypassing the matching iommufd_put_object() used by the normal unmap path. This leaks the object reference taken by iommufd_lock_obj().
Check for internal accesses first so skipped entries are never locked.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 27b77ea5feaa8fcf385ea99ce757982b0ac9d1f0 < 436189ee4bb2c7c993b945d68570dd38c3e4349e | affected |
| Linux | Linux | 27b77ea5feaa8fcf385ea99ce757982b0ac9d1f0 < 50a66a63d1c841ae6b28a4551f642c1bba4c9529 | affected |
| Linux | Linux | 27b77ea5feaa8fcf385ea99ce757982b0ac9d1f0 < 0dbcdf4473a614adbd732d567c9b39ac0e040e0c | affected |
| Linux | Linux | 6.17 | affected |
| Linux | Linux | 0 < 6.17 | unaffected |
| Linux | Linux | 6.18.50 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.4 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/436189ee4bb2c7c993b945d68570dd38c3e4349e
- https://git.kernel.org/stable/c/50a66a63d1c841ae6b28a4551f642c1bba4c9529
- https://git.kernel.org/stable/c/0dbcdf4473a614adbd732d567c9b39ac0e040e0c
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.