« Volver al listado

CVE-2026-90241

Estado: RecibidaAlta (8.2)—

In the Linux kernel, the following vulnerability has been resolved:

iommu/vt-d: Tear down scalable-mode context on probe failure

intel_pasid_setup_sm_context() walks a PCI device’s DMA aliases via pci_for_each_dma_alias() and programs a scalable-mode context entry for each RID. For a device with a dma_alias_mask, the callback is invoked once for the device’s own RID and once for each alias bit, all with the same pci_dev, so device_pasid_table_setup() runs for multiple RIDs.

pci_for_each_dma_alias() stops at the first callback error. Therefore, a failure partway through the walk can leave context entries for already processed RIDs present and still pointing to the device’s PASID table.

Leer descripción completaMostrar menos

On this error path, intel_iommu_probe_device() currently jumps directly to intel_pasid_free_table(), which frees the PASID table without first tearing down those context entries. The IOMMU may then walk a present context entry whose PASID table pointer references freed memory.

intel_iommu_release_device() already performs teardown before freeing the table. Apply the same ordering on the probe failure path.

device_pasid_table_teardown() safely handles RIDs that were never programmed: iommu_context_addr() returns NULL when no context table has been allocated, and clearing the Present bit of an already non-present entry is a no-op. So unwind is safe for both the alias that failed and any aliases not yet reached.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Escalada local de privilegios en kernel Linux (PR:H, AV:L) por fallo en limpieza de entradas IOMMU; riesgo de DoS y corrupción de memoria según descripción técnica.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90241",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.2,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 1.5
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "301f1a80487fd2f51012533792583d4425e8b8c0",
              "lessThan": "25ac85a9747cd63e1d166ace7b360a2cd9479d9d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "301f1a80487fd2f51012533792583d4425e8b8c0",
              "lessThan": "d0e978ced7429b516358bb4d41d337214768ae98",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "301f1a80487fd2f51012533792583d4425e8b8c0",
              "lessThan": "db5daf25f754cdc20c18525adb88240ece6fdee9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "301f1a80487fd2f51012533792583d4425e8b8c0",
              "lessThan": "c509fb73a1093a15accd7d43a61645d4b520f6ac",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/iommu/intel/iommu.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.9"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.9",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/iommu/intel/iommu.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:20.070",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/25ac85a9747cd63e1d166ace7b360a2cd9479d9d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c509fb73a1093a15accd7d43a61645d4b520f6ac",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d0e978ced7429b516358bb4d41d337214768ae98",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/db5daf25f754cdc20c18525adb88240ece6fdee9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Tear down scalable-mode context on probe failure\n\nintel_pasid_setup_sm_context() walks a PCI device’s DMA aliases via\npci_for_each_dma_alias() and programs a scalable-mode context entry for\neach RID. For a device with a dma_alias_mask, the callback is invoked\nonce for the device’s own RID and once for each alias bit, all with the\nsame pci_dev, so device_pasid_table_setup() runs for multiple RIDs.\n\npci_for_each_dma_alias() stops at the first callback error. Therefore, a\nfailure partway through the walk can leave context entries for already\nprocessed RIDs present and still pointing to the device’s PASID table.\n\nOn this error path, intel_iommu_probe_device() currently jumps directly\nto intel_pasid_free_table(), which frees the PASID table without\nfirst tearing down those context entries. The IOMMU may then walk a\npresent context entry whose PASID table pointer references freed\nmemory.\n\nintel_iommu_release_device() already performs teardown before freeing the\ntable. Apply the same ordering on the probe failure path.\n\ndevice_pasid_table_teardown() safely handles RIDs that were never\nprogrammed: iommu_context_addr() returns NULL when no context table has\nbeen allocated, and clearing the Present bit of an already non-present\nentry is a no-op. So unwind is safe for both the alias that failed and\nany aliases not yet reached."
    }
  ],
  "lastModified": "2026-09-18T18:17:50.390",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}