In the Linux kernel, the following vulnerability has been resolved:
iommu/vt-d: Fix race condition during PASID entry replacement
The Intel VT-d PASID table entry is 512 bits (64 bytes). When replacing an active PASID entry (e.g., during domain replacement), the current implementation calculates a new entry on the stack and copies it to the table using a single structure assignment.
struct pasid_entry *pte, new_pte;
pte = intel_pasid_get_entry(dev, pasid); pasid_pte_config_first_level(iommu, &new_pte, ...); *pte = new_pte;
Because the hardware may fetch the 512-bit PASID entry in multiple 128-bit chunks, updating the entire entry while it is active (Present bit set) risks a "torn" read. In this scenario, the IOMMU hardware could observe an inconsistent state — partially new data and partially old data — leading to unpredictable behavior or spurious faults.
Fix this by removing the unsafe "replace" helpers and following the "clear-then-update" flow, which ensures the Present bit is cleared and the required invalidation handshake is completed before the new configuration is applied.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade kernel6.18-develUpgrade bpftool6.18-debuginfoUpgrade perf6.18-debuginfoUpgrade kernel6.18-debuginfo-common-x86_64Upgrade kernel6.18-headersUpgrade kernel6.18-modules-extraUpgrade kernel-livepatch-6.18.39-79.141Upgrade microvm-kernel6.18Upgrade python3-perf6.18-debuginfoUpgrade kernel6.18-tools-develUpgrade kernel6.18-debuginfoUpgrade kernel6.18-toolsUpgrade kernel6.18-modules-extra-commonUpgrade kernel6.18-tools-debuginfoUpgrade kernel6.18Upgrade bpftool6.18Upgrade perf6.18Upgrade kernel6.18-debuginfo-common-aarch64Upgrade python3-perf6.18 | Aug 18, 2026 | May 27, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | May 27, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub