CVE-2026-74520: iommu/iommufd: Fix IOPF group ownership UAF

Greg Kroah-Hartman <[email protected]>
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026081544-CVE-2026-74520-7811@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

iommu/iommufd: Fix IOPF group ownership UAF

iopf_group_alloc() links each last-page IOPF group into the generic IOPF
pending list before invoking the domain fault handler.
iommufd_fault_iopf_handler() also queued an accepted group in the
IOMMUFD deliver list without removing it from the generic pending list.

When detach or HWPT replacement drops the device's IOPF reference count
to zero, an IOMMU driver may call iopf_queue_remove_device(). That
function responds to and frees groups through the generic pending list
without removing the same groups from IOMMUFD's deliver list or response
xarray. A later read, response, or cleanup can then access the freed
group and cause a UAF.

Fix this by dequeuing an accepted group from the generic pending list
before IOMMUFD queues it for userspace response.
Make iopf_group_response() send a response regardless of pending-list
membership, so the dequeued group can still be completed by IOMMUFD.

The Linux kernel CVE team has assigned CVE-2026-74520 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 6.11 with commit 34765cbc679c59ea5d952d738d2d16bf4aadc497 and fixed in 6.18.44 with commit 6da8f37419dd4c456f26fc203f04e000186f4b3d
	Issue introduced in 6.11 with commit 34765cbc679c59ea5d952d738d2d16bf4aadc497 and fixed in 7.1.8 with commit 4e74a369236424114b94cf6a9f5ff9e848b430b4
	Issue introduced in 6.11 with commit 34765cbc679c59ea5d952d738d2d16bf4aadc497 and fixed in 7.2-rc6 with commit 738e6f32e61d80b554e37015ecb7bc620b88001c

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-74520
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/iommu/io-pgfault.c
	drivers/iommu/iommufd/eventq.c
	include/linux/iommu.h


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/6da8f37419dd4c456f26fc203f04e000186f4b3d
	https://git.kernel.org/stable/c/4e74a369236424114b94cf6a9f5ff9e848b430b4
	https://git.kernel.org/stable/c/738e6f32e61d80b554e37015ecb7bc620b88001c
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.