PT-2026-94588 · Linux · Linux Kernel
CVE-2026-90240
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the iommu/vt-d component where the context cache is not flushed with the correct source ID (SID) when tearing down DMA aliases. The functions
domain context clear one() and device pasid table teardown() use the requester ID of the device instead of the specific alias ID when calling intel context flush no pasid(). This results in stale entries remaining in the context cache for aliases other than the device's own RID. In scalable-mode teardown, intel pasid free table() may free a PASID directory still referenced by a stale entry, potentially allowing the IOMMU to access freed memory.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel