CVE-2026-90241

Source
https://cve.org/CVERecord?id=CVE-2026-90241
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90241.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90241
Downstream
Published
2026-09-17T16:07:45Z
Modified
2026-09-18T03:48:36Z
Summary
iommu/vt-d: Tear down scalable-mode context on probe failure
Details

In the Linux kernel, the following vulnerability has been resolved:

iommu/vt-d: Tear down scalable-mode context on probe failure

intel_pasid_setup_sm_context() walks a PCI device’s DMA aliases via pci_for_each_dma_alias() and programs a scalable-mode context entry for each RID. For a device with a dma_alias_mask, the callback is invoked once for the device’s own RID and once for each alias bit, all with the same pci_dev, so device_pasid_table_setup() runs for multiple RIDs.

pci_for_each_dma_alias() stops at the first callback error. Therefore, a failure partway through the walk can leave context entries for already processed RIDs present and still pointing to the device’s PASID table.

On this error path, intel_iommu_probe_device() currently jumps directly to intel_pasid_free_table(), which frees the PASID table without first tearing down those context entries. The IOMMU may then walk a present context entry whose PASID table pointer references freed memory.

intel_iommu_release_device() already performs teardown before freeing the table. Apply the same ordering on the probe failure path.

device_pasid_table_teardown() safely handles RIDs that were never programmed: iommu_context_addr() returns NULL when no context table has been allocated, and clearing the Present bit of an already non-present entry is a no-op. So unwind is safe for both the alias that failed and any aliases not yet reached.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90241.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
301f1a80487fd2f51012533792583d4425e8b8c0
Fixed
25ac85a9747cd63e1d166ace7b360a2cd9479d9d
Fixed
d0e978ced7429b516358bb4d41d337214768ae98
Fixed
db5daf25f754cdc20c18525adb88240ece6fdee9
Fixed
c509fb73a1093a15accd7d43a61645d4b520f6ac

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90241.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.9.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90241.json"