iommu/amd/pgtbl: Fix possible race while increase page table level

Summary

CVECVE-2025-39961
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2025-10-09 13:15:32 UTC
Updated2026-07-30 06:24:01 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: iommu/amd/pgtbl: Fix possible race while increase page table level The AMD IOMMU host page table implementation supports dynamic page table levels (up to 6 levels), starting with a 3-level configuration that expands based on IOVA address. The kernel maintains a root pointer and current page table level to enable proper page table walks in alloc_pte()/fetch_pte() operations. The IOMMU IOVA allocator initially starts with 32-bit address and onces its exhuasted it switches to 64-bit address (max address is determined based on IOMMU and device DMA capability). To support larger IOVA, AMD IOMMU driver increases page table level. But in unmap path (iommu_v1_unmap_pages()), fetch_pte() reads pgtable->[root/mode] without lock. So its possible that in exteme corner case, when increase_address_space() is updating pgtable->[root/mode], fetch_pte() reads wrong page table level (pgtable->mode). It does compare the value with level encoded in page table and returns NULL. This will result is iommu_unmap ops to fail and upper layer may retry/log WARN_ON. CPU 0 CPU 1 ------ ------ map pages unmap pages alloc_pte() -> increase_address_space() iommu_v1_unmap_pages() -> fetch_pte() pgtable->root = pte (new root value) READ pgtable->[mode/root] Reads new root, old mode Updates mode (pgtable->mode += 1) Since Page table level updates are infrequent and already synchronized with a spinlock, implement seqcount to enable lock-free read operations on the read path.

Risk And Classification

Primary CVSS: v3.1 4.7 MEDIUM from [email protected]

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Problem Types: CWE-362


VersionSourceTypeScoreSeverityVector
3.1[email protected]Primary4.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
3.1416baaa9-dc9f-4396-8d5f-8c081fb06d67Secondary8.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
3.1CNADECLARED8.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVSS v3.1 Breakdown

Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Operating System Linux Linux Kernel All All All All

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 754265bcab78a9014f0f99cd35e0d610fcd7dfa7 075abf0b1a958acfbea2435003d228e738e90346 git Not specified
CNA Linux Linux affected 754265bcab78a9014f0f99cd35e0d610fcd7dfa7 cd92c8ab336c3a633d46e6f35ebcd3509ae7db3b git Not specified
CNA Linux Linux affected 754265bcab78a9014f0f99cd35e0d610fcd7dfa7 7d462bdecb7d9c32934dab44aaeb7ea7d73a27a2 git Not specified
CNA Linux Linux affected 754265bcab78a9014f0f99cd35e0d610fcd7dfa7 1e56310b40fd2e7e0b9493da9ff488af145bdd0c git Not specified
CNA Linux Linux affected 6fb92f18555a7b8e085267d513612dc0ff9a5360 git Not specified
CNA Linux Linux affected b15bf74405faa1a65025eb8a6eb337e140e5250a git Not specified
CNA Linux Linux affected 0d50f7b1e8c80a8c20db5049e269468c059b0378 git Not specified
CNA Linux Linux affected 785ca708a908b9c596ede852470ba28b8dc3e40b git Not specified
CNA Linux Linux affected 4.9.194 4.10 semver Not specified
CNA Linux Linux affected 4.14.146 4.15 semver Not specified
CNA Linux Linux affected 4.19.75 4.20 semver Not specified
CNA Linux Linux affected 5.2.17 5.3 semver Not specified
CNA Linux Linux affected 5.3 Not specified
CNA Linux Linux unaffected 5.3 semver Not specified
CNA Linux Linux unaffected 6.6.108 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.49 6.12.* semver Not specified
CNA Linux Linux unaffected 6.16.9 6.16.* semver Not specified
CNA Linux Linux unaffected 6.17 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/075abf0b1a958acfbea2435003d228e738e90346 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/7d462bdecb7d9c32934dab44aaeb7ea7d73a27a2 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/cd92c8ab336c3a633d46e6f35ebcd3509ae7db3b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/1e56310b40fd2e7e0b9493da9ff488af145bdd0c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report