CVE-2026-89448
9.3
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
iommu/vt-d: Force requesting ACS when tboot is enabled
Currently the conditions of requesting ACS in detect_intel_iommu() don't include tboot, leading to a possible misconfiguration with ACS disabled (e.g. due to user opts) while iommu is later forced on by tboot_force_iommu().
Fix it by checking tboot in detect_intel_iommu().
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 5d990b627537e59a3a2f039ff588a4750e9c1a6a < aaeb81241e802c86be69394f72d49fde3f861fbb | affected |
| Linux | Linux | 5d990b627537e59a3a2f039ff588a4750e9c1a6a < 45705a6bfdb283f7b3b509010fd617b72f942537 | affected |
| Linux | Linux | 5d990b627537e59a3a2f039ff588a4750e9c1a6a < 87bc611c6c98a41c00feb7b06b0c297dd141a2ae | affected |
| Linux | Linux | 5d990b627537e59a3a2f039ff588a4750e9c1a6a < 607432b2618b61df81134be0ef2562b8300c1216 | affected |
| Linux | Linux | 2.6.33 | affected |
| Linux | Linux | 0 < 2.6.33 | unaffected |
| Linux | Linux | 6.12.109 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.50 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.4 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/aaeb81241e802c86be69394f72d49fde3f861fbb
- https://git.kernel.org/stable/c/45705a6bfdb283f7b3b509010fd617b72f942537
- https://git.kernel.org/stable/c/87bc611c6c98a41c00feb7b06b0c297dd141a2ae
- https://git.kernel.org/stable/c/607432b2618b61df81134be0ef2562b8300c1216
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.