CVE-2026-74439
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/08/2026
Last modified:
15/08/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry<br />
<br />
device_pasid_table_teardown() zeroes the 128-bit scalable-mode context<br />
entry with context_clear_entry() while the Present bit is still set. This<br />
creates a window where the hardware can fetch a torn entry, with some<br />
fields already zeroed while Present is still set, leading to unpredictable<br />
behavior or spurious faults. The context-cache invalidation is issued only<br />
after the entry has been zeroed, and intel_pasid_free_table() then frees<br />
the PASID directory pages, so the IOMMU can keep walking a stale Present=1<br />
entry that points at freed memory.<br />
<br />
While x86 provides strong write ordering, the compiler may reorder the two<br />
64-bit writes to the entry, and the hardware fetch is not guaranteed to be<br />
atomic with respect to multiple CPU writes.<br />
<br />
Commit c1e4f1dccbe9d ("iommu/vt-d: Clear Present bit before tearing down<br />
context entry") fixed this exact pattern in domain_context_clear_one() and<br />
the copied-context path, but device_pasid_table_teardown() was not<br />
converted.<br />
<br />
Align it with the "Guidance to Software for Invalidations" in the VT-d<br />
spec, Section 6.5.3.3, using the same ownership handshake as the sibling<br />
fix: clear only the Present bit, flush it to the IOMMU, perform the<br />
context-cache invalidation, and only then zero the rest of the entry.



