From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C7C1457F732 for ; Fri, 11 Sep 2026 19:52:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156340; cv=none; b=eMNodzxixLTbJP2pTeZNfaKRX+eRekbsywEOXGHjYoRh3GbuzCtTMDe5N/XlFPLKV6/HDt3U8rjWtus71FEjJiVgz5X6iJG8AqRF/HU/UICoUZHX6DPq6zk4HFO28dXSa8J6dZaBSdEzaXZIeaZ1ev4Wj59hH0CbS0hYsu2MlS4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156340; c=relaxed/simple; bh=wfY/3SjXgFzaOwfhY6iONCmfIQBiDv+YwqYjpsglJw4=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=X300j9D6hYaOXpC3i1wX8MSCTfExh4wtTW8wrMRcGgvVcmJMeWaNfsE/rl3nRCbIi5p542aKbkP2GM1mgMTAzlN2unUD3auMNXLFpDFWVDj/MFmBMyiAtBONRBxeh7fxQ1AVIyjB+I7kDqPrKH434vAodjUtyGfXDs6At5OCGUo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=PaB/AckP; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="PaB/AckP" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 2AAAE1F00893; Fri, 11 Sep 2026 19:52:09 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156330; bh=uXD8wnYt1LWroO4i0ayDlk92TR0op6GHK4EwIdp6Q8M=; h=From:To:Cc:Subject:Date:Reply-To; b=PaB/AckPhjx//QSvOZ+HhXiTPfIvulEp8QqWaMgzcxVslDxmbFqalcunIBb1s4JwD cKsPODegEbTxiTHEw167Uv8c3G43H7FqaFuLJYG/sArGzv8VT/6tKlO+9tZpHDV43J IeWRXMKzabyheUEQ5/jfPlzPCdPxjj1A/+5SzD3U= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89447: iommufd: Avoid locking internal accesses during unmap Date: Fri, 11 Sep 2026 21:42:16 +0200 Message-ID: <2026091157-CVE-2026-89447-334e@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2517; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=8W3XNwlZWzkUq+t9xbCvxM+hj9OWNhTE62eZHd4yIVo=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIj23JrkqWlaaRJz/dfVBQkiYz06G3HTezsemjPNWS i45pOvaEcvCIMjEICumyPJlG8/R/RWHFL0MbU/DzGFlAhnCwMUpABM5Lswwz+Dk9ENlqlYztFm4 3kxZENn1JeFXNMM8pVePjqzkzT1wLax8RpUNY8lr3tnOAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: iommufd: Avoid locking internal accesses during unmap iommufd_access_notify_unmap() skips internal accesses because they do not have an external unmap callback to invoke. However, the current test calls iommufd_lock_obj() before checking whether the access is internal. If iommufd_lock_obj() succeeds, the loop then sees the internal access and continues, bypassing the matching iommufd_put_object() used by the normal unmap path. This leaks the object reference taken by iommufd_lock_obj(). Check for internal accesses first so skipped entries are never locked. The Linux kernel CVE team has assigned CVE-2026-89447 to this issue. Affected and fixed versions =========================== Issue introduced in 6.17 with commit 27b77ea5feaa8fcf385ea99ce757982b0ac9d1f0 and fixed in 6.18.50 with commit 436189ee4bb2c7c993b945d68570dd38c3e4349e Issue introduced in 6.17 with commit 27b77ea5feaa8fcf385ea99ce757982b0ac9d1f0 and fixed in 7.2.4 with commit 50a66a63d1c841ae6b28a4551f642c1bba4c9529 Issue introduced in 6.17 with commit 27b77ea5feaa8fcf385ea99ce757982b0ac9d1f0 and fixed in 7.3-rc1 with commit 0dbcdf4473a614adbd732d567c9b39ac0e040e0c Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89447 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/iommu/iommufd/device.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/436189ee4bb2c7c993b945d68570dd38c3e4349e https://git.kernel.org/stable/c/50a66a63d1c841ae6b28a4551f642c1bba4c9529 https://git.kernel.org/stable/c/0dbcdf4473a614adbd732d567c9b39ac0e040e0c