{"api_version":"1","generated_at":"2026-08-15T16:26:57+00:00","cve":"CVE-2026-74520","urls":{"html":"https://cve.report/CVE-2026-74520","api":"https://cve.report/api/cve/CVE-2026-74520.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-74520","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-74520"},"summary":{"title":"iommu/iommufd: Fix IOPF group ownership UAF","description":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/iommufd: Fix IOPF group ownership UAF\n\niopf_group_alloc() links each last-page IOPF group into the generic IOPF\npending list before invoking the domain fault handler.\niommufd_fault_iopf_handler() also queued an accepted group in the\nIOMMUFD deliver list without removing it from the generic pending list.\n\nWhen detach or HWPT replacement drops the device's IOPF reference count\nto zero, an IOMMU driver may call iopf_queue_remove_device(). That\nfunction responds to and frees groups through the generic pending list\nwithout removing the same groups from IOMMUFD's deliver list or response\nxarray. A later read, response, or cleanup can then access the freed\ngroup and cause a UAF.\n\nFix this by dequeuing an accepted group from the generic pending list\nbefore IOMMUFD queues it for userspace response.\nMake iopf_group_response() send a response regardless of pending-list\nmembership, so the dequeued group can still be completed by IOMMUFD.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-15 13:17:57","updated_at":"2026-08-15 13:17:57"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/738e6f32e61d80b554e37015ecb7bc620b88001c","name":"https://git.kernel.org/stable/c/738e6f32e61d80b554e37015ecb7bc620b88001c","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/6da8f37419dd4c456f26fc203f04e000186f4b3d","name":"https://git.kernel.org/stable/c/6da8f37419dd4c456f26fc203f04e000186f4b3d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/4e74a369236424114b94cf6a9f5ff9e848b430b4","name":"https://git.kernel.org/stable/c/4e74a369236424114b94cf6a9f5ff9e848b430b4","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-74520","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74520","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 34765cbc679c59ea5d952d738d2d16bf4aadc497 6da8f37419dd4c456f26fc203f04e000186f4b3d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 34765cbc679c59ea5d952d738d2d16bf4aadc497 4e74a369236424114b94cf6a9f5ff9e848b430b4 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 34765cbc679c59ea5d952d738d2d16bf4aadc497 738e6f32e61d80b554e37015ecb7bc620b88001c git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.11","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.11 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.44 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.8 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2-rc6 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/iommu/io-pgfault.c","drivers/iommu/iommufd/eventq.c","include/linux/iommu.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"6da8f37419dd4c456f26fc203f04e000186f4b3d","status":"affected","version":"34765cbc679c59ea5d952d738d2d16bf4aadc497","versionType":"git"},{"lessThan":"4e74a369236424114b94cf6a9f5ff9e848b430b4","status":"affected","version":"34765cbc679c59ea5d952d738d2d16bf4aadc497","versionType":"git"},{"lessThan":"738e6f32e61d80b554e37015ecb7bc620b88001c","status":"affected","version":"34765cbc679c59ea5d952d738d2d16bf4aadc497","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/iommu/io-pgfault.c","drivers/iommu/iommufd/eventq.c","include/linux/iommu.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.11"},{"lessThan":"6.11","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.44","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.8","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2-rc6","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.44","versionStartIncluding":"6.11","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.8","versionStartIncluding":"6.11","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2-rc6","versionStartIncluding":"6.11","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/iommufd: Fix IOPF group ownership UAF\n\niopf_group_alloc() links each last-page IOPF group into the generic IOPF\npending list before invoking the domain fault handler.\niommufd_fault_iopf_handler() also queued an accepted group in the\nIOMMUFD deliver list without removing it from the generic pending list.\n\nWhen detach or HWPT replacement drops the device's IOPF reference count\nto zero, an IOMMU driver may call iopf_queue_remove_device(). That\nfunction responds to and frees groups through the generic pending list\nwithout removing the same groups from IOMMUFD's deliver list or response\nxarray. A later read, response, or cleanup can then access the freed\ngroup and cause a UAF.\n\nFix this by dequeuing an accepted group from the generic pending list\nbefore IOMMUFD queues it for userspace response.\nMake iopf_group_response() send a response regardless of pending-list\nmembership, so the dequeued group can still be completed by IOMMUFD."}],"providerMetadata":{"dateUpdated":"2026-08-15T12:27:38.712Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/6da8f37419dd4c456f26fc203f04e000186f4b3d"},{"url":"https://git.kernel.org/stable/c/4e74a369236424114b94cf6a9f5ff9e848b430b4"},{"url":"https://git.kernel.org/stable/c/738e6f32e61d80b554e37015ecb7bc620b88001c"}],"title":"iommu/iommufd: Fix IOPF group ownership UAF","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-74520","datePublished":"2026-08-15T12:27:38.712Z","dateReserved":"2026-08-15T05:44:03.911Z","dateUpdated":"2026-08-15T12:27:38.712Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-15 13:17:57","lastModifiedDate":"2026-08-15 13:17:57","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"74520","Ordinal":"1","Title":"iommu/iommufd: Fix IOPF group ownership UAF","CVE":"CVE-2026-74520","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"74520","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/iommufd: Fix IOPF group ownership UAF\n\niopf_group_alloc() links each last-page IOPF group into the generic IOPF\npending list before invoking the domain fault handler.\niommufd_fault_iopf_handler() also queued an accepted group in the\nIOMMUFD deliver list without removing it from the generic pending list.\n\nWhen detach or HWPT replacement drops the device's IOPF reference count\nto zero, an IOMMU driver may call iopf_queue_remove_device(). That\nfunction responds to and frees groups through the generic pending list\nwithout removing the same groups from IOMMUFD's deliver list or response\nxarray. A later read, response, or cleanup can then access the freed\ngroup and cause a UAF.\n\nFix this by dequeuing an accepted group from the generic pending list\nbefore IOMMUFD queues it for userspace response.\nMake iopf_group_response() send a response regardless of pending-list\nmembership, so the dequeued group can still be completed by IOMMUFD.","Type":"Description","Title":"iommu/iommufd: Fix IOPF group ownership UAF"}]}}}