CVE 8.8 HIGH

iommu/vt-d: Fix race condition during PASID entry replacement_CVE-2026-45945

8.8 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

In the Linux kernel, the following vulnerability has been resolved:

iommu/vt-d: Fix race condition during PASID entry replacement

The Intel VT-d PASID table entry is 512 bits (64 bytes). When replacing
an active PASID entry (e.g., during domain replacement), the current
implementation calculates a new entry on the stack and copies it to the
table using a single structure assignment.

struct pasid_entry *pte, new_pte;

pte = intel_pasid_get_entry(dev, pasid);
pasid_pte_config_first_level(iommu, &new_pte, ...);
*pte = new_pte;

Because the hardware may fetch the 512-bit PASID entry in multiple
128-bit chunks, updating the entire entry while it is active (Present
bit set) risks a "torn" read. In this scenario, the IOMMU hardware
could observe an inconsistent state — partially new data and partially
old data — leading to unpredictable behavior or spurious faults.

Fix this by removing the unsafe "replace" helpers and following the
"clear-then-update" flow, which ensures the Present bit is cleared and
the required invalidation handshake is completed before the new
configuration is applied.

Basic Information

ID CVE-2026-45945
Source Linux
Published May 27, 2026 at 12:18
Modified May 30, 2026 at 10:46

Affected Product

Vendor Linux
Product Linux
Version 7543ee63e8113aa34b07df3b16b3b9d2c5f73939
Affected Versions Linux Linux 7543ee63e8113aa34b07df3b16b3b9d2c5f73939
Linux Linux 7543ee63e8113aa34b07df3b16b3b9d2c5f73939
Linux Linux 6.13

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.