← All Advisories

CVE-2026-89445

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-89445

Key Details

CVECVE-2026-89445
CVSS Score / Version8.8 (High) / CVSS v3.1
Updated2026-10-03
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

iommufd: Fix UAF in selftest IOPF reporting

IOMMUFD selftest TRIGGER_IOPF borrows an attach handle from

group->pasid_array without synchronizing against PASID detach,

then a concurrent iommu_report_device_fault() can dereference

that borrowed handle's domain pointer after the detach erases

the handle and frees the backing struct iommufd_attach_handle.

TRIGGER_IOPF then dereferences the freed handle, causing a UAF.

Fix by adding a iopf_rwsem in mock_dev to follow the expected design

of a real driver. Hold its read side across the whole

iommu_report_device_fault() call, and its write side around every

path that attaches, detaches, or replaces a device domain.

This can block new reports and drains in-flight reports before an old

attach handle or the IOPF fault parameter can be removed.

Also take the write side while registering a mock device, since

it can invoke the mock driver's default-domain attach callback. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-89445
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-89445