🔐 CVE Alert

CVE-2026-90241

UNKNOWN 0.0

iommu/vt-d: Tear down scalable-mode context on probe failure

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Tear down scalable-mode context on probe failure intel_pasid_setup_sm_context() walks a PCI device’s DMA aliases via pci_for_each_dma_alias() and programs a scalable-mode context entry for each RID. For a device with a dma_alias_mask, the callback is invoked once for the device’s own RID and once for each alias bit, all with the same pci_dev, so device_pasid_table_setup() runs for multiple RIDs. pci_for_each_dma_alias() stops at the first callback error. Therefore, a failure partway through the walk can leave context entries for already processed RIDs present and still pointing to the device’s PASID table. On this error path, intel_iommu_probe_device() currently jumps directly to intel_pasid_free_table(), which frees the PASID table without first tearing down those context entries. The IOMMU may then walk a present context entry whose PASID table pointer references freed memory. intel_iommu_release_device() already performs teardown before freeing the table. Apply the same ordering on the probe failure path. device_pasid_table_teardown() safely handles RIDs that were never programmed: iommu_context_addr() returns NULL when no context table has been allocated, and clearing the Present bit of an already non-present entry is a no-op. So unwind is safe for both the alias that failed and any aliases not yet reached.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Linux / Linux
301f1a80487fd2f51012533792583d4425e8b8c0 < 25ac85a9747cd63e1d166ace7b360a2cd9479d9d 301f1a80487fd2f51012533792583d4425e8b8c0 < d0e978ced7429b516358bb4d41d337214768ae98 301f1a80487fd2f51012533792583d4425e8b8c0 < db5daf25f754cdc20c18525adb88240ece6fdee9 301f1a80487fd2f51012533792583d4425e8b8c0 < c509fb73a1093a15accd7d43a61645d4b520f6ac
Linux / Linux
6.9

References

NVD ↗ CVE.org ↗ EPSS Data ↗
git.kernel.org: https://git.kernel.org/stable/c/25ac85a9747cd63e1d166ace7b360a2cd9479d9d git.kernel.org: https://git.kernel.org/stable/c/d0e978ced7429b516358bb4d41d337214768ae98 git.kernel.org: https://git.kernel.org/stable/c/db5daf25f754cdc20c18525adb88240ece6fdee9 git.kernel.org: https://git.kernel.org/stable/c/c509fb73a1093a15accd7d43a61645d4b520f6ac