CVE-2026-89446

Updated on 11 Sep 2026

Severity

Awaiting Analysis

Details

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved:

iommufd: Release current IOAS on xa_store() failure

iommufd_take_all_iova_rwsem() takes an object reference and the iova_rwsem write lock before storing the IOAS in the temporary ioas_list xarray.

If xa_store() fails, the current IOAS has not been inserted into ioas_list yet. iommufd_release_all_iova_rwsem() only unwinds IOAS objects already present in that xarray, so it cannot release the current IOAS.

Release the current IOAS rwsem and object reference before unwinding the previously stored entries.

Details

Affected product:
Debian 10 ELS , Debian 11 ELS
Affected packages:
linux @ 4.19.0 (+1 more)