PT-2026-94592 · Linux · Linux Kernel
CVE-2026-90244
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the IOMMU DMA subsystem where concurrent access to the
msi page list can lead to data corruption. In VFIO type1 legacy containers, newly attached groups may be merged into an existing domain if their IOMMU operations and cache-coherency enforcement match. Because the iommu dma get msi page() function only asserts that the caller's own group mutex is held, multiple devices within the same merged domain can enter this function simultaneously. This is particularly relevant for IOMMUs that publish IOMMU RESV SW MSI, such as ARM SMMU, where guest drivers probing and allocating MSIs in parallel can cause concurrent execution and subsequent corruption of the msi page list.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel