PT-2026-94588 · Linux · Linux Kernel

CVE-2026-90240

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the iommu/vt-d component where the context cache is not flushed with the correct source ID (SID) when tearing down DMA aliases. The functions domain context clear one() and device pasid table teardown() use the requester ID of the device instead of the specific alias ID when calling intel context flush no pasid(). This results in stale entries remaining in the context cache for aliases other than the device's own RID. In scalable-mode teardown, intel pasid free table() may free a PASID directory still referenced by a stale entry, potentially allowing the IOMMU to access freed memory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-90240
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel