← Späť na vyhľadávanie CVE

CVE-2026-45894

Intel VT-d

Popis

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Clear Present bit before tearing down PASID entry The Intel VT-d Scalable Mode PASID table entry consists of 512 bits (64 bytes). When tearing down an entry, the current implementation zeros the entire 64-byte structure immediately using multiple 64-bit writes. Since the IOMMU hardware may fetch these 64 bytes using multiple internal transactions (e.g., four 128-bit bursts), updating or zeroing the entire entry while it is active (P=1) risks a -torn- read. If a hardware fetch occurs simultaneously with the CPU zeroing the entry, the hardware could observe an inconsistent state, leading to unpredictable behavior or spurious faults. Follow the -Guidance to Software for Invalidations- in the VT-d spec (Section 6.5.3.3) by implementing the recommended ownership handshake: 1. Clear only the -Present- (P) bit of the PASID entry. 2. Use a dma_wmb() to ensure the cleared bit is visible to hardware before proceeding...

CVSS 7.8EPSS 0.149%Riziko 0.79
Zobraziť zdroj
Zverejnené
2026-05-27 14:17:03
Dotknuté verzie
unknown
Typ
Firmvér
Vektor
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Operačné systémy
Linux