« Volver al listado

CVE-2026-80894

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace

iommufd_hwpt_replace_device() calls:

passing the *new* hwpt together with the handle of the device's *old* domain. This should be a parameter mismatch:

Fix this by passing "old" instead.

Detalles técnicos trazas, registros y código del informe original
	iommufd_auto_response_faults(hwpt, old_handle);

1. Semantically, iommufd_auto_response_faults(x, handle) scans
   x->fault's deliver list and response xarray for groups matching
   "handle". A group is queued under the hwpt that was attached at
   fault-delivery time. old_handle is fetched *before* the domain switch,
   so its group lives on old->fault, not on the new hwpt->fault.

2. Historically, the first argument was "old". The routine was
   introduced by commit b7d8833677ba ("iommufd: Fault-capable hwpt
   attach/detach/replace") as __fault_domain_replace_dev() in
   fault.c, correctly calling iommufd_auto_response_faults(old, curr).
   Commit fb21b1568ada ("iommufd: Make attach_handle generic than
   fault specific") moved this into iommufd_hwpt_replace_device() in
   device.c and swapped it to "hwpt". This should be a refactor regression,
   not an intentional change.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80894",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6d11543bf37abdf60b8e6022a62fccfb82a5fe2e",
              "lessThan": "adb87155b67f9759ff010c0a99559f5bffa45dcf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fb21b1568adaa76af7a8c853f37c60fba8b28661",
              "lessThan": "564ac339c0f8bada4e77a57a92bab9d3df635e07",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fb21b1568adaa76af7a8c853f37c60fba8b28661",
              "lessThan": "8eb077025279304268bd58657f0af3d388822b21",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fb21b1568adaa76af7a8c853f37c60fba8b28661",
              "lessThan": "ba5c0f28a26e7d9be1e0997f8920dd638e2782fd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1e0216b6a58c79b5ee91c78706d5f560e4d1f56f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4b23c4b991eb90cc7bca42e9f81142feedd4bb56",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.12.24",
              "lessThan": "6.12.105",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.13.12",
              "lessThan": "6.14",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.14.3",
              "lessThan": "6.15",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/iommu/iommufd/device.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.105",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.44",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/iommu/iommufd/device.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-04T18:17:57.603",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/564ac339c0f8bada4e77a57a92bab9d3df635e07",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8eb077025279304268bd58657f0af3d388822b21",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/adb87155b67f9759ff010c0a99559f5bffa45dcf",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ba5c0f28a26e7d9be1e0997f8920dd638e2782fd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\niommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace\n\niommufd_hwpt_replace_device() calls:\n\n\tiommufd_auto_response_faults(hwpt, old_handle);\n\npassing the *new* hwpt together with the handle of\nthe device's *old* domain. This should be a parameter mismatch:\n\n1. Semantically, iommufd_auto_response_faults(x, handle) scans\n   x->fault's deliver list and response xarray for groups matching\n   \"handle\". A group is queued under the hwpt that was attached at\n   fault-delivery time. old_handle is fetched *before* the domain switch,\n   so its group lives on old->fault, not on the new hwpt->fault.\n\n2. Historically, the first argument was \"old\". The routine was\n   introduced by commit b7d8833677ba (\"iommufd: Fault-capable hwpt\n   attach/detach/replace\") as __fault_domain_replace_dev() in\n   fault.c, correctly calling iommufd_auto_response_faults(old, curr).\n   Commit fb21b1568ada (\"iommufd: Make attach_handle generic than\n   fault specific\") moved this into iommufd_hwpt_replace_device() in\n   device.c and swapped it to \"hwpt\". This should be a refactor regression,\n   not an intentional change.\n\nFix this by passing \"old\" instead."
    }
  ],
  "lastModified": "2026-09-04T18:17:57.603",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}