« Volver al listado

CVE-2026-43220

Estado: ModificadaMedia (5.5)—

In the Linux kernel, the following vulnerability has been resolved:

iommu/amd: serialize sequence allocation under concurrent TLB invalidations

With concurrent TLB invalidations, completion wait randomly gets timed out because cmd_sem_val was incremented outside the IOMMU spinlock, allowing CMD_COMPL_WAIT commands to be queued out of sequence and breaking the ordering assumption in wait_on_sem(). Move the cmd_sem_val increment under iommu->lock so completion sequence allocation is serialized with command queuing. And remove the unnecessary return.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-43220",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "f2f65b28d802a667119147444ec2ae33eebf9a58",
              "lessThan": "d51bf43193b1e95dc4e34e540dc76e19def2ae5a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "715c263119fd1b918a9fcbd8a36ea5b604a46324",
              "lessThan": "fca7aa0264ae99e5ff287d0ced5af0b82b121c4f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e15768e68820142077bbca402d8e902f64ade1b0",
              "lessThan": "5000ce7fcb31067566a1a1a2e5b5bbff93625242",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "496269d12072ecb219826485bdbec70c92a8eef5",
              "lessThan": "48caa7542a795c9679ec1bd1bc2592e05a7369a4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d2a0cac10597068567d336e85fa3cbdbe8ca62bf",
              "lessThan": "9e249c48412828e807afddc21527eb734dc9bd3d",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/iommu/amd/amd_iommu_types.h",
            "drivers/iommu/amd/init.c",
            "drivers/iommu/amd/iommu.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.6.128",
              "lessThan": "6.6.140",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.12.75",
              "lessThan": "6.12.88",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/iommu/amd/amd_iommu_types.h",
            "drivers/iommu/amd/init.c",
            "drivers/iommu/amd/iommu.c"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-05-06T12:16:41.660",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/48caa7542a795c9679ec1bd1bc2592e05a7369a4",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5000ce7fcb31067566a1a1a2e5b5bbff93625242",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9e249c48412828e807afddc21527eb734dc9bd3d",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d51bf43193b1e95dc4e34e540dc76e19def2ae5a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fca7aa0264ae99e5ff287d0ced5af0b82b121c4f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/amd: serialize sequence allocation under concurrent TLB invalidations\n\nWith concurrent TLB invalidations, completion wait randomly gets timed out\nbecause cmd_sem_val was incremented outside the IOMMU spinlock, allowing\nCMD_COMPL_WAIT commands to be queued out of sequence and breaking the\nordering assumption in wait_on_sem().\nMove the cmd_sem_val increment under iommu->lock so completion sequence\nallocation is serialized with command queuing.\nAnd remove the unnecessary return."
    }
  ],
  "lastModified": "2026-06-17T10:49:10.677",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B503BA3C-31FA-4897-85F6-EECE0EE4668F",
              "versionEndExcluding": "6.7",
              "versionStartIncluding": "6.6.128"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "72DA13D5-CC16-4529-9803-274233ABE12C",
              "versionEndExcluding": "6.13",
              "versionStartIncluding": "6.12.75"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}