CVE-2026-45862 (GCVE-0-2026-45862)
Vulnerability from cvelistv5
Published
2026-05-27 12:15
Modified
2026-08-05 12:28
Summary
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Flush cache for PASID table before using it When writing the address of a freshly allocated zero-initialized PASID table to a PASID directory entry, do that after the CPU cache flush for this PASID table, not before it, to avoid the time window when this PASID table may be already used by non-coherent IOMMU hardware while its contents in RAM is still some random old data, not zero-initialized.
Impacted products
Vendor Product Version
Linux Linux Version: 7e00b52c8cdd9d3a985d63d72ecae7bde6314883
Version: 5c65f097124770c3e5b9b83ed1a8b68c119bc7b5
Version: 2bed9455db7cc0ab7ece6b3d846472097b52855a
Version: 194b3348bdbb7db65375c72f3f774aee4cc6614e
Version: 194b3348bdbb7db65375c72f3f774aee4cc6614e
Version: 194b3348bdbb7db65375c72f3f774aee4cc6614e
Version: 194b3348bdbb7db65375c72f3f774aee4cc6614e
Version: 194b3348bdbb7db65375c72f3f774aee4cc6614e
Version: 1b48c70feefc499b62670521efa002ab01e05df5
Version: bc348a6cc8f92e9979fbfbb3c6b48fd51b4b1dbf
Version: 5.10.175   
Version: 5.15.103   
Version: 6.1.16   
Version: 5.4.237   
Version: 6.2.3   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/iommu/intel/pasid.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "cd75e77125c8a51754ca4cd60b4ca083ed735d1d",
              "status": "affected",
              "version": "7e00b52c8cdd9d3a985d63d72ecae7bde6314883",
              "versionType": "git"
            },
            {
              "lessThan": "0616137b70e6d9a547d4b60df8e1b64e36d83661",
              "status": "affected",
              "version": "5c65f097124770c3e5b9b83ed1a8b68c119bc7b5",
              "versionType": "git"
            },
            {
              "lessThan": "36990407cdd257473607e33802d00e978af2759e",
              "status": "affected",
              "version": "2bed9455db7cc0ab7ece6b3d846472097b52855a",
              "versionType": "git"
            },
            {
              "lessThan": "c93f23375d8c410954b0df825e814b632fd62b9d",
              "status": "affected",
              "version": "194b3348bdbb7db65375c72f3f774aee4cc6614e",
              "versionType": "git"
            },
            {
              "lessThan": "5962c30a6f05ea1ab73f039e235bb30716243517",
              "status": "affected",
              "version": "194b3348bdbb7db65375c72f3f774aee4cc6614e",
              "versionType": "git"
            },
            {
              "lessThan": "36244dfd3853f7bf89d03b8e90d56b23ce7fbc16",
              "status": "affected",
              "version": "194b3348bdbb7db65375c72f3f774aee4cc6614e",
              "versionType": "git"
            },
            {
              "lessThan": "d15cda135148ea7ba929cfdbcf208182bc29a7aa",
              "status": "affected",
              "version": "194b3348bdbb7db65375c72f3f774aee4cc6614e",
              "versionType": "git"
            },
            {
              "lessThan": "22d169bdd2849fe6bd18c2643742e1c02be6451c",
              "status": "affected",
              "version": "194b3348bdbb7db65375c72f3f774aee4cc6614e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1b48c70feefc499b62670521efa002ab01e05df5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bc348a6cc8f92e9979fbfbb3c6b48fd51b4b1dbf",
              "versionType": "git"
            },
            {
              "lessThan": "5.10.252",
              "status": "affected",
              "version": "5.10.175",
              "versionType": "semver"
            },
            {
              "lessThan": "5.15.202",
              "status": "affected",
              "version": "5.15.103",
              "versionType": "semver"
            },
            {
              "lessThan": "6.1.165",
              "status": "affected",
              "version": "6.1.16",
              "versionType": "semver"
            },
            {
              "lessThan": "5.5",
              "status": "affected",
              "version": "5.4.237",
              "versionType": "semver"
            },
            {
              "lessThan": "6.3",
              "status": "affected",
              "version": "6.2.3",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/iommu/intel/pasid.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.3"
            },
            {
              "lessThan": "6.3",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.252",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.202",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.165",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.128",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.75",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.14",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.19.*",
              "status": "unaffected",
              "version": "6.19.4",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.0",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.252",
                  "versionStartIncluding": "5.10.175",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.202",
                  "versionStartIncluding": "5.15.103",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.165",
                  "versionStartIncluding": "6.1.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.128",
                  "versionStartIncluding": "6.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.75",
                  "versionStartIncluding": "6.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.14",
                  "versionStartIncluding": "6.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.19.4",
                  "versionStartIncluding": "6.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0",
                  "versionStartIncluding": "6.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "5.4.237",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "6.2.3",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Flush cache for PASID table before using it\n\nWhen writing the address of a freshly allocated zero-initialized PASID\ntable to a PASID directory entry, do that after the CPU cache flush for\nthis PASID table, not before it, to avoid the time window when this\nPASID table may be already used by non-coherent IOMMU hardware while\nits contents in RAM is still some random old data, not zero-initialized."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable PASID-table allocation is reached locally via IOMMU domain attach (SVA bind through an accelerator device, or guest/IOMMUFD device setup) using syscalls/ioctls; there is no network-facing path to this code.\nAC:H - Exploitation requires non-coherent VT-d hardware and winning a nanosecond-scale cache-writeback race in which the IOMMU must read the entry before the CPU flushes the zeroes to RAM, with the stale data happening to form a usable present entry \u2014 conditions governed by microarchitectural timing the attacker cannot control.\nPR:L - An unprivileged local user with access to an SVA-capable accelerator device can drive `iommu_sva_bind_device` to trigger the PASID-table allocation while controlling the device\u0027s DMA; no real root is required.\nUI:N - The allocation and the device DMA are driven entirely by the attacker; no victim interaction is needed.\nS:C - The IOMMU enforces the DMA isolation boundary; using stale garbage PASID entries lets a device\u0027s DMA escape its assigned domain, impacting host physical memory in a different security authority \u2014 an IOMMU/DMA boundary bypass.\nC:H - A misdirected DMA translated through a garbage page table can read arbitrary host physical memory, yielding disclosure beyond the device\u0027s domain.\nI:H - The same misdirected DMA path provides write access to arbitrary host physical memory, allowing corruption of kernel data outside the device\u0027s intended domain.\nA:H - Garbage PASID entries can cause IOMMU faults, DMA failures, and memory corruption leading to oops/panic or device/system hangs."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:28:37.806Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/cd75e77125c8a51754ca4cd60b4ca083ed735d1d"
        },
        {
          "url": "https://git.kernel.org/stable/c/0616137b70e6d9a547d4b60df8e1b64e36d83661"
        },
        {
          "url": "https://git.kernel.org/stable/c/36990407cdd257473607e33802d00e978af2759e"
        },
        {
          "url": "https://git.kernel.org/stable/c/c93f23375d8c410954b0df825e814b632fd62b9d"
        },
        {
          "url": "https://git.kernel.org/stable/c/5962c30a6f05ea1ab73f039e235bb30716243517"
        },
        {
          "url": "https://git.kernel.org/stable/c/36244dfd3853f7bf89d03b8e90d56b23ce7fbc16"
        },
        {
          "url": "https://git.kernel.org/stable/c/d15cda135148ea7ba929cfdbcf208182bc29a7aa"
        },
        {
          "url": "https://git.kernel.org/stable/c/22d169bdd2849fe6bd18c2643742e1c02be6451c"
        }
      ],
      "title": "iommu/vt-d: Flush cache for PASID table before using it",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-45862",
    "datePublished": "2026-05-27T12:15:41.903Z",
    "dateReserved": "2026-05-13T15:03:33.080Z",
    "dateUpdated": "2026-08-05T12:28:37.806Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…