PT-2026-51846 · Linux+2 · Linux Kernel+2
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A race condition exists in the Input/Output Memory Management Unit (IOMMU) subsystem, which manages how devices access system memory. This occurs during device recovery when multiple memory domains are attached concurrently. Specifically, the
iommu group set domain internal() function rejects concurrent domain attachments if any device in the group is recovering, which triggers a WARN ON in iommu group set domain nofail(). This can lead to a Use-After-Free (UAF) condition—where the system attempts to use memory that has already been released—potentially allowing a local attacker to execute unauthorized code or cause a system crash (denial of service).Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Assertion Failure
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu