CVE-2026-89447
In the Linux kernel, the following vulnerability has been resolved:
iommufd: Avoid locking internal accesses during unmap
iommufd_access_notify_unmap() skips internal accesses because they do not have an external unmap callback to invoke.
However, the current test calls iommufd_lock_obj() before checking whether the access is internal. If iommufd_lock_obj() succeeds, the loop then sees the internal access and continues, bypassing the matching iommufd_put_object() used by the normal unmap path. This leaks the object reference taken by iommufd_lock_obj().
Check for internal accesses first so skipped entries are never locked.
CVSS
NVD hasn't assigned a CVSS score to this CVE (common since the April 2026 policy change).
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.22%
- Percentile among all scored CVEs: 11
- Score date: 10/4/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
References
Raw JSON (NVD)
Show
{
"id": "CVE-2026-89447",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "27b77ea5feaa8fcf385ea99ce757982b0ac9d1f0",
"lessThan": "436189ee4bb2c7c993b945d68570dd38c3e4349e",
"versionType": "git"
},
{
"status": "affected",
"version": "27b77ea5feaa8fcf385ea99ce757982b0ac9d1f0",
"lessThan": "50a66a63d1c841ae6b28a4551f642c1bba4c9529",
"versionType": "git"
},
{
"status": "affected",
"version": "27b77ea5feaa8fcf385ea99ce757982b0ac9d1f0",
"lessThan": "0dbcdf4473a614adbd732d567c9b39ac0e040e0c",
"versionType": "git"
}
],
"programFiles": [
"drivers/iommu/iommufd/device.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.17"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.17",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.50",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.4",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/iommu/iommufd/device.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-11T20:19:25.227",
"references": [
{
"url": "https://git.kernel.org/stable/c/0dbcdf4473a614adbd732d567c9b39ac0e040e0c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/436189ee4bb2c7c993b945d68570dd38c3e4349e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/50a66a63d1c841ae6b28a4551f642c1bba4c9529",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\niommufd: Avoid locking internal accesses during unmap\n\niommufd_access_notify_unmap() skips internal accesses because they do\nnot have an external unmap callback to invoke.\n\nHowever, the current test calls iommufd_lock_obj() before checking\nwhether the access is internal. If iommufd_lock_obj() succeeds, the loop\nthen sees the internal access and continues, bypassing the matching\niommufd_put_object() used by the normal unmap path. This leaks the\nobject reference taken by iommufd_lock_obj().\n\nCheck for internal accesses first so skipped entries are never locked."
}
],
"lastModified": "2026-09-11T20:19:25.227",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}