CVE-2026-90240
In the Linux kernel, the following vulnerability has been resolved:
iommu/vt-d: Flush context cache with correct SID when tearing down aliases
domain_context_clear_one() and device_pasid_table_teardown() are both invoked once per DMA alias of a device. Each function locates the context entry using the bus/devfn pair provided by the pci_for_each_dma_alias() callback, then calls intel_context_flush_no_pasid(), which constructs a device-selective context-cache invalidation from info->bus and info->devfn (that is, always the requester ID of the device itself).
As a result, for every alias other than the device’s own RID, the context entry that was just cleared in memory is never invalidated in the context cache.
Leer descripción completaMostrar menos
Hardware may continue using that stale cached entry. In the scalable-mode teardown path, intel_pasid_free_table() can then free the PASID directory still referenced by that stale entry, allowing the IOMMU to walk freed memory.
Fix this by passing the source ID of the entry being torn down to intel_context_flush_no_pasid(), instead of deriving it from @info.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation75 % - Impacto principal
T1499.004Application or System Exploitationimpact60 % - Impacto secundario
T1565.001Stored Data Manipulationimpact50 %
Vulnerabilidad local en kernel (AV:L, PR:L) que permite escalada mediante uso incorrecto de cachés IOMMU; hardware puede acceder memoria liberada, causando DoS o corrupción de datos.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-90240",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 2
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "f90584f4beb84211c4d21b319cc13f391fe9f3c2",
"lessThan": "a803141597d61dc0511f7cd849625e17d042ca8a",
"versionType": "git"
},
{
"status": "affected",
"version": "f90584f4beb84211c4d21b319cc13f391fe9f3c2",
"lessThan": "5baddf100b3be730912485648cbaae5e3a251923",
"versionType": "git"
},
{
"status": "affected",
"version": "f90584f4beb84211c4d21b319cc13f391fe9f3c2",
"lessThan": "c54e4ae971b98e8d650400137d332cee56c03f55",
"versionType": "git"
}
],
"programFiles": [
"drivers/iommu/intel/iommu.c",
"drivers/iommu/intel/iommu.h",
"drivers/iommu/intel/pasid.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.11",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/iommu/intel/iommu.c",
"drivers/iommu/intel/iommu.h",
"drivers/iommu/intel/pasid.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:17:19.960",
"references": [
{
"url": "https://git.kernel.org/stable/c/5baddf100b3be730912485648cbaae5e3a251923",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a803141597d61dc0511f7cd849625e17d042ca8a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c54e4ae971b98e8d650400137d332cee56c03f55",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Flush context cache with correct SID when tearing down aliases\n\ndomain_context_clear_one() and device_pasid_table_teardown() are both\ninvoked once per DMA alias of a device. Each function locates the context\nentry using the bus/devfn pair provided by the pci_for_each_dma_alias()\ncallback, then calls intel_context_flush_no_pasid(), which constructs a\ndevice-selective context-cache invalidation from info->bus and\ninfo->devfn (that is, always the requester ID of the device itself).\n\nAs a result, for every alias other than the device’s own RID, the context\nentry that was just cleared in memory is never invalidated in the context\ncache. Hardware may continue using that stale cached entry. In the\nscalable-mode teardown path, intel_pasid_free_table() can then free the\nPASID directory still referenced by that stale entry, allowing the IOMMU\nto walk freed memory.\n\nFix this by passing the source ID of the entry being torn down to\nintel_context_flush_no_pasid(), instead of deriving it from @info."
}
],
"lastModified": "2026-09-18T18:17:50.190",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}