{"api_version":"1","generated_at":"2026-08-15T02:30:14+00:00","cve":"CVE-2026-68347","urls":{"html":"https://cve.report/CVE-2026-68347","api":"https://cve.report/api/cve/CVE-2026-68347.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-68347","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-68347"},"summary":{"title":"iommu/amd: Fix IRQ unsafe locking in gdom allocation","description":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/amd: Fix IRQ unsafe locking in gdom allocation\n\nLockdep complains:\n\n  [  259.410489] =====================================================\n  [  259.417287] WARNING: HARDIRQ-safe -> HARDIRQ-unsafe lock order detected\n  [  259.424667] 7.0.0-g51db1d8d2113 #54 Not tainted\n  [  259.429718] -----------------------------------------------------\n  [  259.436516] qemu-system-x86/10143 [HC0[0]:SC0[0]:HE0:SE1] is trying to acquire:\n  [  259.444670] ff3b2b1c60305170 (&xa->xa_lock#25){+.+.}-{3:3}, at: __domain_flush_pages+0x17c/0x4b0\n  [  259.454485]\n                 and this task is already holding:\n  [  259.460991] ff3b2b1c98504cc0 (&domain->lock){-.-.}-{3:3}, at: amd_iommu_iotlb_sync+0x25/0x60\n  [  259.470408] which would create a new lock dependency:\n  [  259.476041]  (&domain->lock){-.-.}-{3:3} -> (&xa->xa_lock#25){+.+.}-{3:3}\n  [  259.483615]\n                 but this new dependency connects a HARDIRQ-irq-safe lock:\n  [  259.492447]  (&domain->lock){-.-.}-{3:3}\n  [  259.492449]\n                 ... which became HARDIRQ-irq-safe at:\n  [  259.503705]   lock_acquire+0xb6/0x2e0\n  [  259.507790]   _raw_spin_lock_irqsave+0x3e/0x60\n  [  259.512748]   amd_iommu_flush_iotlb_all+0x20/0x50\n  [  259.517996]   iommu_dma_free_iova.isra.0+0x1b8/0x1e0\n  [  259.523534]   __iommu_dma_unmap+0xc2/0x140\n  [  259.528100]   iommu_dma_unmap_phys+0x55/0xc0\n  [  259.532863]   dma_unmap_phys+0x274/0x2e0\n  [  259.537238]   dma_unmap_page_attrs+0x17/0x30\n  [  259.542000]   nvme_unmap_data+0x13e/0x280\n  [  259.546473]   nvme_pci_complete_batch+0x45/0x70\n  [  259.551524]   nvme_irq+0x83/0x90\n  [  259.555123]   __handle_irq_event_percpu+0x92/0x360\n  [  259.560466]   handle_irq_event+0x39/0x80\n  [  259.564841]   handle_edge_irq+0xb2/0x1a0\n  [  259.569214]   __common_interrupt+0x4e/0x130\n  [  259.573882]   common_interrupt+0x88/0xa0\n  [  259.578256]   asm_common_interrupt+0x27/0x40\n  [  259.583019]   cpuidle_enter_state+0x119/0x5d0\n  [  259.587877]   cpuidle_enter+0x2e/0x50\n  [  259.591962]   do_idle+0x153/0x2c0\n  [  259.595657]   cpu_startup_entry+0x29/0x30\n  [  259.600128]   start_secondary+0x118/0x150\n  [  259.604601]   common_startup_64+0x13e/0x141\n  [  259.609266]\n                 to a HARDIRQ-irq-unsafe lock:\n  [  259.615384]  (&xa->xa_lock#25){+.+.}-{3:3}\n  [  259.615386]\n                 ... which became HARDIRQ-irq-unsafe at:\n  [  259.627039] ...\n  [  259.627039]   lock_acquire+0xb6/0x2e0\n  [  259.633071]   _raw_spin_lock+0x2f/0x50\n  [  259.637250]   amd_iommu_alloc_domain_nested+0x140/0x3c0\n  [  259.643078]   iommufd_hwpt_alloc+0x272/0x800 [iommufd]\n  [  259.648813]   iommufd_fops_ioctl+0x14e/0x200 [iommufd]\n  [  259.654547]   __x64_sys_ioctl+0x9d/0xf0\n  ...\n\nSince amd_iommu_domain_flush_pages() necessarily holds domain->lock to do the\nflush, switch the allocation side in gdom_info_load_or_alloc_locked() to\nHARDIRQ-safe allocation. The IOMMU_DESTROY->free path has the same issue,\nso switch that path to HARDIRQ-safe locking as well.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-10 13:20:26","updated_at":"2026-08-10 13:20:26"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/0db3a430d9681fdb29890bef6934cd89cd1745d0","name":"https://git.kernel.org/stable/c/0db3a430d9681fdb29890bef6934cd89cd1745d0","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/e0c78cdf35af3ada05f9309f4641e9f83c945dbd","name":"https://git.kernel.org/stable/c/e0c78cdf35af3ada05f9309f4641e9f83c945dbd","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-68347","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68347","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 757d2b1fdf5b7d6eead5963a49b5780617987ab8 e0c78cdf35af3ada05f9309f4641e9f83c945dbd git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 757d2b1fdf5b7d6eead5963a49b5780617987ab8 0db3a430d9681fdb29890bef6934cd89cd1745d0 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7.0","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.0 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.6 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2-rc5 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/iommu/amd/nested.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"e0c78cdf35af3ada05f9309f4641e9f83c945dbd","status":"affected","version":"757d2b1fdf5b7d6eead5963a49b5780617987ab8","versionType":"git"},{"lessThan":"0db3a430d9681fdb29890bef6934cd89cd1745d0","status":"affected","version":"757d2b1fdf5b7d6eead5963a49b5780617987ab8","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/iommu/amd/nested.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"7.0"},{"lessThan":"7.0","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2-rc5","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.6","versionStartIncluding":"7.0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2-rc5","versionStartIncluding":"7.0","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/amd: Fix IRQ unsafe locking in gdom allocation\n\nLockdep complains:\n\n  [  259.410489] =====================================================\n  [  259.417287] WARNING: HARDIRQ-safe -> HARDIRQ-unsafe lock order detected\n  [  259.424667] 7.0.0-g51db1d8d2113 #54 Not tainted\n  [  259.429718] -----------------------------------------------------\n  [  259.436516] qemu-system-x86/10143 [HC0[0]:SC0[0]:HE0:SE1] is trying to acquire:\n  [  259.444670] ff3b2b1c60305170 (&xa->xa_lock#25){+.+.}-{3:3}, at: __domain_flush_pages+0x17c/0x4b0\n  [  259.454485]\n                 and this task is already holding:\n  [  259.460991] ff3b2b1c98504cc0 (&domain->lock){-.-.}-{3:3}, at: amd_iommu_iotlb_sync+0x25/0x60\n  [  259.470408] which would create a new lock dependency:\n  [  259.476041]  (&domain->lock){-.-.}-{3:3} -> (&xa->xa_lock#25){+.+.}-{3:3}\n  [  259.483615]\n                 but this new dependency connects a HARDIRQ-irq-safe lock:\n  [  259.492447]  (&domain->lock){-.-.}-{3:3}\n  [  259.492449]\n                 ... which became HARDIRQ-irq-safe at:\n  [  259.503705]   lock_acquire+0xb6/0x2e0\n  [  259.507790]   _raw_spin_lock_irqsave+0x3e/0x60\n  [  259.512748]   amd_iommu_flush_iotlb_all+0x20/0x50\n  [  259.517996]   iommu_dma_free_iova.isra.0+0x1b8/0x1e0\n  [  259.523534]   __iommu_dma_unmap+0xc2/0x140\n  [  259.528100]   iommu_dma_unmap_phys+0x55/0xc0\n  [  259.532863]   dma_unmap_phys+0x274/0x2e0\n  [  259.537238]   dma_unmap_page_attrs+0x17/0x30\n  [  259.542000]   nvme_unmap_data+0x13e/0x280\n  [  259.546473]   nvme_pci_complete_batch+0x45/0x70\n  [  259.551524]   nvme_irq+0x83/0x90\n  [  259.555123]   __handle_irq_event_percpu+0x92/0x360\n  [  259.560466]   handle_irq_event+0x39/0x80\n  [  259.564841]   handle_edge_irq+0xb2/0x1a0\n  [  259.569214]   __common_interrupt+0x4e/0x130\n  [  259.573882]   common_interrupt+0x88/0xa0\n  [  259.578256]   asm_common_interrupt+0x27/0x40\n  [  259.583019]   cpuidle_enter_state+0x119/0x5d0\n  [  259.587877]   cpuidle_enter+0x2e/0x50\n  [  259.591962]   do_idle+0x153/0x2c0\n  [  259.595657]   cpu_startup_entry+0x29/0x30\n  [  259.600128]   start_secondary+0x118/0x150\n  [  259.604601]   common_startup_64+0x13e/0x141\n  [  259.609266]\n                 to a HARDIRQ-irq-unsafe lock:\n  [  259.615384]  (&xa->xa_lock#25){+.+.}-{3:3}\n  [  259.615386]\n                 ... which became HARDIRQ-irq-unsafe at:\n  [  259.627039] ...\n  [  259.627039]   lock_acquire+0xb6/0x2e0\n  [  259.633071]   _raw_spin_lock+0x2f/0x50\n  [  259.637250]   amd_iommu_alloc_domain_nested+0x140/0x3c0\n  [  259.643078]   iommufd_hwpt_alloc+0x272/0x800 [iommufd]\n  [  259.648813]   iommufd_fops_ioctl+0x14e/0x200 [iommufd]\n  [  259.654547]   __x64_sys_ioctl+0x9d/0xf0\n  ...\n\nSince amd_iommu_domain_flush_pages() necessarily holds domain->lock to do the\nflush, switch the allocation side in gdom_info_load_or_alloc_locked() to\nHARDIRQ-safe allocation. The IOMMU_DESTROY->free path has the same issue,\nso switch that path to HARDIRQ-safe locking as well."}],"providerMetadata":{"dateUpdated":"2026-08-10T12:03:24.020Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/e0c78cdf35af3ada05f9309f4641e9f83c945dbd"},{"url":"https://git.kernel.org/stable/c/0db3a430d9681fdb29890bef6934cd89cd1745d0"}],"title":"iommu/amd: Fix IRQ unsafe locking in gdom allocation","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-68347","datePublished":"2026-08-10T12:03:24.020Z","dateReserved":"2026-07-30T09:28:09.384Z","dateUpdated":"2026-08-10T12:03:24.020Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-10 13:20:26","lastModifiedDate":"2026-08-10 13:20:26","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"68347","Ordinal":"1","Title":"iommu/amd: Fix IRQ unsafe locking in gdom allocation","CVE":"CVE-2026-68347","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"68347","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/amd: Fix IRQ unsafe locking in gdom allocation\n\nLockdep complains:\n\n  [  259.410489] =====================================================\n  [  259.417287] WARNING: HARDIRQ-safe -> HARDIRQ-unsafe lock order detected\n  [  259.424667] 7.0.0-g51db1d8d2113 #54 Not tainted\n  [  259.429718] -----------------------------------------------------\n  [  259.436516] qemu-system-x86/10143 [HC0[0]:SC0[0]:HE0:SE1] is trying to acquire:\n  [  259.444670] ff3b2b1c60305170 (&xa->xa_lock#25){+.+.}-{3:3}, at: __domain_flush_pages+0x17c/0x4b0\n  [  259.454485]\n                 and this task is already holding:\n  [  259.460991] ff3b2b1c98504cc0 (&domain->lock){-.-.}-{3:3}, at: amd_iommu_iotlb_sync+0x25/0x60\n  [  259.470408] which would create a new lock dependency:\n  [  259.476041]  (&domain->lock){-.-.}-{3:3} -> (&xa->xa_lock#25){+.+.}-{3:3}\n  [  259.483615]\n                 but this new dependency connects a HARDIRQ-irq-safe lock:\n  [  259.492447]  (&domain->lock){-.-.}-{3:3}\n  [  259.492449]\n                 ... which became HARDIRQ-irq-safe at:\n  [  259.503705]   lock_acquire+0xb6/0x2e0\n  [  259.507790]   _raw_spin_lock_irqsave+0x3e/0x60\n  [  259.512748]   amd_iommu_flush_iotlb_all+0x20/0x50\n  [  259.517996]   iommu_dma_free_iova.isra.0+0x1b8/0x1e0\n  [  259.523534]   __iommu_dma_unmap+0xc2/0x140\n  [  259.528100]   iommu_dma_unmap_phys+0x55/0xc0\n  [  259.532863]   dma_unmap_phys+0x274/0x2e0\n  [  259.537238]   dma_unmap_page_attrs+0x17/0x30\n  [  259.542000]   nvme_unmap_data+0x13e/0x280\n  [  259.546473]   nvme_pci_complete_batch+0x45/0x70\n  [  259.551524]   nvme_irq+0x83/0x90\n  [  259.555123]   __handle_irq_event_percpu+0x92/0x360\n  [  259.560466]   handle_irq_event+0x39/0x80\n  [  259.564841]   handle_edge_irq+0xb2/0x1a0\n  [  259.569214]   __common_interrupt+0x4e/0x130\n  [  259.573882]   common_interrupt+0x88/0xa0\n  [  259.578256]   asm_common_interrupt+0x27/0x40\n  [  259.583019]   cpuidle_enter_state+0x119/0x5d0\n  [  259.587877]   cpuidle_enter+0x2e/0x50\n  [  259.591962]   do_idle+0x153/0x2c0\n  [  259.595657]   cpu_startup_entry+0x29/0x30\n  [  259.600128]   start_secondary+0x118/0x150\n  [  259.604601]   common_startup_64+0x13e/0x141\n  [  259.609266]\n                 to a HARDIRQ-irq-unsafe lock:\n  [  259.615384]  (&xa->xa_lock#25){+.+.}-{3:3}\n  [  259.615386]\n                 ... which became HARDIRQ-irq-unsafe at:\n  [  259.627039] ...\n  [  259.627039]   lock_acquire+0xb6/0x2e0\n  [  259.633071]   _raw_spin_lock+0x2f/0x50\n  [  259.637250]   amd_iommu_alloc_domain_nested+0x140/0x3c0\n  [  259.643078]   iommufd_hwpt_alloc+0x272/0x800 [iommufd]\n  [  259.648813]   iommufd_fops_ioctl+0x14e/0x200 [iommufd]\n  [  259.654547]   __x64_sys_ioctl+0x9d/0xf0\n  ...\n\nSince amd_iommu_domain_flush_pages() necessarily holds domain->lock to do the\nflush, switch the allocation side in gdom_info_load_or_alloc_locked() to\nHARDIRQ-safe allocation. The IOMMU_DESTROY->free path has the same issue,\nso switch that path to HARDIRQ-safe locking as well.","Type":"Description","Title":"iommu/amd: Fix IRQ unsafe locking in gdom allocation"}]}}}