CVE-2026-90241
CVE CVE-2026-90241EUVD EUVD-2026-81834Published 2026-09-17T16:07:45.000ZLast changed 2026-09-18T17:54:05.000ZCVSS 8.2
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Tear down scalable-mode context on probe failure intel_pasid_setup_sm_context() walks a PCI device’s DMA aliases via pci_for_each_dma_alias() and programs a scalable-mode context entry for each RID. For a device with a dma_alias_mask, the callback is invoked once for the device’s own RID and once for each alias bit, all with the same pci_dev, so device_pasid_table_setup() runs for multiple RIDs. pci_for_each_dma_alias() stops at the first callback error. Therefore, a failure partway through the walk can leave context entries for already processed RIDs present and still pointing to the device’s PASID table. On this error path, intel_iommu_probe_device() currently jumps directly to intel_pasid_free_table(), which frees the PASID table without first tearing down those context entries. The IOMMU may then walk a present context entry whose PASID table pointer references freed memory. intel_iommu_release_device() already performs teardown before freeing the table. Apply the same ordering on the probe failure path. device_pasid_table_teardown() safely handles RIDs that were never programmed: iommu_context_addr() returns NULL when no context table has been allocated, and clearing the Present bit of an already non-present entry is a no-op. So unwind is safe for both the alias that failed and any aliases not yet reached.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 301f1a80487fd2f51012533792583d4425e8b8c0 <c509fb73a1093a15accd7d43a61645d4b520f6ac; 301f1a80487fd2f51012533792583d4425e8b8c0 <d0e978ced7429b516358bb4d41d337214768ae98; 301f1a80487fd2f51012533792583d4425e8b8c0 <25ac85a9747cd63e1d166ace7b360a2cd9479d9d; patch: 0; patch: 7.3-rc1; patch: 6.18.52; 6.9; 301f1a80487fd2f51012533792583d4425e8b8c0 <db5daf25f754cdc20c18525adb88240ece6fdee9; patch: 6.12.110; patch: 7.2.6
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.