{"api_version":"1","generated_at":"2026-10-01T13:40:29+00:00","cve":"CVE-2026-90240","urls":{"html":"https://cve.report/CVE-2026-90240","api":"https://cve.report/api/cve/CVE-2026-90240.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-90240","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-90240"},"summary":{"title":"iommu/vt-d: Flush context cache with correct SID when tearing down aliases","description":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Flush context cache with correct SID when tearing down aliases\n\ndomain_context_clear_one() and device_pasid_table_teardown() are both\ninvoked once per DMA alias of a device. Each function locates the context\nentry using the bus/devfn pair provided by the pci_for_each_dma_alias()\ncallback, then calls intel_context_flush_no_pasid(), which constructs a\ndevice-selective context-cache invalidation from info->bus and\ninfo->devfn (that is, always the requester ID of the device itself).\n\nAs a result, for every alias other than the device’s own RID, the context\nentry that was just cleared in memory is never invalidated in the context\ncache. Hardware may continue using that stale cached entry. In the\nscalable-mode teardown path, intel_pasid_free_table() can then free the\nPASID directory still referenced by that stale entry, allowing the IOMMU\nto walk freed memory.\n\nFix this by passing the source ID of the entry being torn down to\nintel_context_flush_no_pasid(), instead of deriving it from @info.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-17 17:17:19","updated_at":"2026-09-18 18:17:50"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","data":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/5baddf100b3be730912485648cbaae5e3a251923","name":"https://git.kernel.org/stable/c/5baddf100b3be730912485648cbaae5e3a251923","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/a803141597d61dc0511f7cd849625e17d042ca8a","name":"https://git.kernel.org/stable/c/a803141597d61dc0511f7cd849625e17d042ca8a","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/c54e4ae971b98e8d650400137d332cee56c03f55","name":"https://git.kernel.org/stable/c/c54e4ae971b98e8d650400137d332cee56c03f55","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-90240","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90240","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f90584f4beb84211c4d21b319cc13f391fe9f3c2 a803141597d61dc0511f7cd849625e17d042ca8a git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f90584f4beb84211c4d21b319cc13f391fe9f3c2 5baddf100b3be730912485648cbaae5e3a251923 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f90584f4beb84211c4d21b319cc13f391fe9f3c2 c54e4ae971b98e8d650400137d332cee56c03f55 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.11","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.11 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.52 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.6 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"90240","cve":"CVE-2026-90240","epss":"0.001610000","percentile":"0.057620000","score_date":"2026-09-21","updated_at":"2026-09-22 00:03:19"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/iommu/intel/iommu.c","drivers/iommu/intel/iommu.h","drivers/iommu/intel/pasid.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"a803141597d61dc0511f7cd849625e17d042ca8a","status":"affected","version":"f90584f4beb84211c4d21b319cc13f391fe9f3c2","versionType":"git"},{"lessThan":"5baddf100b3be730912485648cbaae5e3a251923","status":"affected","version":"f90584f4beb84211c4d21b319cc13f391fe9f3c2","versionType":"git"},{"lessThan":"c54e4ae971b98e8d650400137d332cee56c03f55","status":"affected","version":"f90584f4beb84211c4d21b319cc13f391fe9f3c2","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/iommu/intel/iommu.c","drivers/iommu/intel/iommu.h","drivers/iommu/intel/pasid.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.11"},{"lessThan":"6.11","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.52","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.52","versionStartIncluding":"6.11","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.6","versionStartIncluding":"6.11","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"6.11","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Flush context cache with correct SID when tearing down aliases\n\ndomain_context_clear_one() and device_pasid_table_teardown() are both\ninvoked once per DMA alias of a device. Each function locates the context\nentry using the bus/devfn pair provided by the pci_for_each_dma_alias()\ncallback, then calls intel_context_flush_no_pasid(), which constructs a\ndevice-selective context-cache invalidation from info->bus and\ninfo->devfn (that is, always the requester ID of the device itself).\n\nAs a result, for every alias other than the device’s own RID, the context\nentry that was just cleared in memory is never invalidated in the context\ncache. Hardware may continue using that stale cached entry. In the\nscalable-mode teardown path, intel_pasid_free_table() can then free the\nPASID directory still referenced by that stale entry, allowing the IOMMU\nto walk freed memory.\n\nFix this by passing the source ID of the entry being torn down to\nintel_context_flush_no_pasid(), instead of deriving it from @info."}],"metrics":[{"cvssV3_1":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - domain_context_clear_one() and device_pasid_table_teardown() run from local VFIO_DEVICE_DETACH_IOMMUFD_PT/ATTACH_IOMMUFD_PT (vfio_df_ioctl_detach_pt → iommufd_device_detach → blocking_domain_attach_dev → device_block_translation) and from intel_iommu_release_device on PCI removal. The bug is intel_context_flush_no_pasid() using the wrong SID, not bytes from a remote protocol.\nAC:L - For every pci_for_each_dma_alias() RID other than info->bus/info->devfn, intel_context_flush_no_pasid() issues DMA_CCMD_DEVICE_INVL with the device's own RID, so the alias context-cache entry is never invalidated. A VFIO user who owns a dma_alias_mask or PCI-bridge-aliased device then DMAs with that alias SID; there is no uncontrolled race.\nPR:L - vfio_device_fops_unl_ioctl handles VFIO_DEVICE_DETACH_IOMMUFD_PT with no capable() check; vfio_group_fops_open requires CAP_SYS_RAWIO only for VFIO_NO_IOMMU groups. A tenant VMM with a passed-through aliased PCI device (device-file access, not init-namespace root) can detach while keeping DMA active.\nUI:N - The attacker issues VFIO_DEVICE_DETACH_IOMMUFD_PT or closes the vfio device fd themselves, then continues DMA using the unflushed alias RID. No separate victim action such as mounting a filesystem is required.\nS:C - After the missed alias-SID flush, hardware keeps a Present context for that RID while intel_pasid_free_table() (scalable mode) or domain teardown (legacy domain_context_clear_one) frees the PASID directory or page tables. The IOMMU then walks those freed translation structures for device DMA, crossing the VT-d DMA isolation boundary.\nC:H - A stale cached context for the alias SID still points at the PASID directory that intel_pasid_free_table() just freed, or at second-level page tables already torn down. Device DMA with that RID is translated through attacker-influencable freed pages, reading host memory outside the assigned domain.\nI:H - The same leftover cached page-table or PASID-directory pointer for the unflushed alias SID lets the device DMA-write host memory that software has already freed or reassigned, giving an arbitrary cross-domain write primitive.\nA:H - IOMMU walks of the freed PASID directory or page tables via the stale alias-SID context cause DMAR faults, translation failures, and host oops/panic; the commit documents hardware continuing to use that cached entry after teardown."}]}],"providerMetadata":{"dateUpdated":"2026-09-18T17:54:04.466Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/a803141597d61dc0511f7cd849625e17d042ca8a"},{"url":"https://git.kernel.org/stable/c/5baddf100b3be730912485648cbaae5e3a251923"},{"url":"https://git.kernel.org/stable/c/c54e4ae971b98e8d650400137d332cee56c03f55"}],"title":"iommu/vt-d: Flush context cache with correct SID when tearing down aliases","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-90240","datePublished":"2026-09-17T16:07:44.445Z","dateReserved":"2026-09-11T19:38:34.795Z","dateUpdated":"2026-09-18T17:54:04.466Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-17 17:17:19","lastModifiedDate":"2026-09-18 18:17:50","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2,"impactScore":6}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"90240","Ordinal":"1","Title":"iommu/vt-d: Flush context cache with correct SID when tearing do","CVE":"CVE-2026-90240","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"90240","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Flush context cache with correct SID when tearing down aliases\n\ndomain_context_clear_one() and device_pasid_table_teardown() are both\ninvoked once per DMA alias of a device. Each function locates the context\nentry using the bus/devfn pair provided by the pci_for_each_dma_alias()\ncallback, then calls intel_context_flush_no_pasid(), which constructs a\ndevice-selective context-cache invalidation from info->bus and\ninfo->devfn (that is, always the requester ID of the device itself).\n\nAs a result, for every alias other than the device’s own RID, the context\nentry that was just cleared in memory is never invalidated in the context\ncache. Hardware may continue using that stale cached entry. In the\nscalable-mode teardown path, intel_pasid_free_table() can then free the\nPASID directory still referenced by that stale entry, allowing the IOMMU\nto walk freed memory.\n\nFix this by passing the source ID of the entry being torn down to\nintel_context_flush_no_pasid(), instead of deriving it from @info.","Type":"Description","Title":"iommu/vt-d: Flush context cache with correct SID when tearing do"}]}}}