* CVE-2026-89451: iommu/sva: Set handle->dev before the SVA handle is visible
@ 2026-09-11 19:42 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-11 19:42 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
iommu/sva: Set handle->dev before the SVA handle is visible
iommu_attach_device_pasid() installs the new SVA attach handle in the
group PASID lookup before iommu_sva_bind_device() returns. A concurrent
bind can therefore find and reuse the same handle after iommu_sva_lock is
dropped.
handle->dev was initialized after dropping iommu_sva_lock. This leaves a
window where a racing bind can return a handle whose dev pointer is still
NULL. A subsequent iommu_sva_unbind_device() can then dereference it via
handle->dev->iommu_group.
Initialize handle->dev before releasing iommu_sva_lock so any visible SVA
handle is fully initialized.
The Linux kernel CVE team has assigned CVE-2026-89451 to this issue.
Affected and fixed versions
===========================
Issue introduced in 6.2 with commit be51b1d6bbff48c7d1943a8ff1e5a55777807f6e and fixed in 6.12.109 with commit bcffb1c75da8fc9d51168ff9f09d471c26507912
Issue introduced in 6.2 with commit be51b1d6bbff48c7d1943a8ff1e5a55777807f6e and fixed in 6.18.50 with commit 968e9a1f71140c86dc4092f6b361e997923f3813
Issue introduced in 6.2 with commit be51b1d6bbff48c7d1943a8ff1e5a55777807f6e and fixed in 7.2.4 with commit 37a96a30617a4c96f048a5874c00509bc4fe4d85
Issue introduced in 6.2 with commit be51b1d6bbff48c7d1943a8ff1e5a55777807f6e and fixed in 7.3-rc1 with commit 530f8f9c3546cb3ebee1b135375aaee08a073ebb
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-89451
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
drivers/iommu/iommu-sva.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/bcffb1c75da8fc9d51168ff9f09d471c26507912
https://git.kernel.org/stable/c/968e9a1f71140c86dc4092f6b361e997923f3813
https://git.kernel.org/stable/c/37a96a30617a4c96f048a5874c00509bc4fe4d85
https://git.kernel.org/stable/c/530f8f9c3546cb3ebee1b135375aaee08a073ebb
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-09-11 19:50 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-11 19:42 CVE-2026-89451: iommu/sva: Set handle->dev before the SVA handle is visible Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.