{"api_version":"1","generated_at":"2026-10-05T17:59:07+00:00","cve":"CVE-2026-90242","urls":{"html":"https://cve.report/CVE-2026-90242","api":"https://cve.report/api/cve/CVE-2026-90242.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-90242","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-90242"},"summary":{"title":"iommu/vt-d: Fix iopf_refcount leak on RID domain replacement","description":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Fix iopf_refcount leak on RID domain replacement\n\nintel_iommu_attach_device() enables IOPF for the new domain but never\ndisables it for the old one.  device_block_translation(), called at the\nstart of the function, tears down translation but does not touch any IOPF\nstate; blocking_domain_attach_dev() has to call iopf_for_domain_remove()\nexplicitly before invoking it for exactly this reason.\n\nidentity_domain_attach_dev() has the same problem.  Its comment claims\nthat no PRI handling is needed because the device has been put in the\nblocking state, but the blocking state and the IOPF reference count are\nindependent of each other.\n\nAs a result, replacing a domain that has an iopf_handler with another\ndomain at RID level leaks a reference in info->iopf_refcount.  The count\nnever drops back to zero, so iopf_queue_remove_device() is never called\nand iommu_disable_pci_pri() triggers its WARN_ON(info->iopf_refcount)\nwhen the device is released.\n\nThe PASID paths already handle this correctly by way of\niopf_for_domain_replace(); convert the two RID paths to do the same.\nUsing the replace helper rather than a bare remove keeps the enable\nbefore the disable, so the reference count does not transiently reach\nzero and evict the device from the IOPF queue.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-17 17:17:20","updated_at":"2026-09-17 17:17:20"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/143cd37ce76527ddd6f6dbac4a89bde31fb8b0dc","name":"https://git.kernel.org/stable/c/143cd37ce76527ddd6f6dbac4a89bde31fb8b0dc","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/236dd58fabd2e951b940a6ad88b81147899ed311","name":"https://git.kernel.org/stable/c/236dd58fabd2e951b940a6ad88b81147899ed311","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-90242","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90242","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 17fce9d2336d952b95474248303e5e7d9777f2e0 143cd37ce76527ddd6f6dbac4a89bde31fb8b0dc git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 17fce9d2336d952b95474248303e5e7d9777f2e0 236dd58fabd2e951b940a6ad88b81147899ed311 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.16","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.16 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.6 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/iommu/intel/iommu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"143cd37ce76527ddd6f6dbac4a89bde31fb8b0dc","status":"affected","version":"17fce9d2336d952b95474248303e5e7d9777f2e0","versionType":"git"},{"lessThan":"236dd58fabd2e951b940a6ad88b81147899ed311","status":"affected","version":"17fce9d2336d952b95474248303e5e7d9777f2e0","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/iommu/intel/iommu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.16"},{"lessThan":"6.16","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.6","versionStartIncluding":"6.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"6.16","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Fix iopf_refcount leak on RID domain replacement\n\nintel_iommu_attach_device() enables IOPF for the new domain but never\ndisables it for the old one.  device_block_translation(), called at the\nstart of the function, tears down translation but does not touch any IOPF\nstate; blocking_domain_attach_dev() has to call iopf_for_domain_remove()\nexplicitly before invoking it for exactly this reason.\n\nidentity_domain_attach_dev() has the same problem.  Its comment claims\nthat no PRI handling is needed because the device has been put in the\nblocking state, but the blocking state and the IOPF reference count are\nindependent of each other.\n\nAs a result, replacing a domain that has an iopf_handler with another\ndomain at RID level leaks a reference in info->iopf_refcount.  The count\nnever drops back to zero, so iopf_queue_remove_device() is never called\nand iommu_disable_pci_pri() triggers its WARN_ON(info->iopf_refcount)\nwhen the device is released.\n\nThe PASID paths already handle this correctly by way of\niopf_for_domain_replace(); convert the two RID paths to do the same.\nUsing the replace helper rather than a bare remove keeps the enable\nbefore the disable, so the reference count does not transiently reach\nzero and evict the device from the IOPF queue."}],"providerMetadata":{"dateUpdated":"2026-09-17T16:07:45.817Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/143cd37ce76527ddd6f6dbac4a89bde31fb8b0dc"},{"url":"https://git.kernel.org/stable/c/236dd58fabd2e951b940a6ad88b81147899ed311"}],"title":"iommu/vt-d: Fix iopf_refcount leak on RID domain replacement","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-90242","datePublished":"2026-09-17T16:07:45.817Z","dateReserved":"2026-09-11T19:38:34.795Z","dateUpdated":"2026-09-17T16:07:45.817Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-17 17:17:20","lastModifiedDate":"2026-09-17 17:17:20","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"90242","Ordinal":"1","Title":"iommu/vt-d: Fix iopf_refcount leak on RID domain replacement","CVE":"CVE-2026-90242","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"90242","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Fix iopf_refcount leak on RID domain replacement\n\nintel_iommu_attach_device() enables IOPF for the new domain but never\ndisables it for the old one.  device_block_translation(), called at the\nstart of the function, tears down translation but does not touch any IOPF\nstate; blocking_domain_attach_dev() has to call iopf_for_domain_remove()\nexplicitly before invoking it for exactly this reason.\n\nidentity_domain_attach_dev() has the same problem.  Its comment claims\nthat no PRI handling is needed because the device has been put in the\nblocking state, but the blocking state and the IOPF reference count are\nindependent of each other.\n\nAs a result, replacing a domain that has an iopf_handler with another\ndomain at RID level leaks a reference in info->iopf_refcount.  The count\nnever drops back to zero, so iopf_queue_remove_device() is never called\nand iommu_disable_pci_pri() triggers its WARN_ON(info->iopf_refcount)\nwhen the device is released.\n\nThe PASID paths already handle this correctly by way of\niopf_for_domain_replace(); convert the two RID paths to do the same.\nUsing the replace helper rather than a bare remove keeps the enable\nbefore the disable, so the reference count does not transiently reach\nzero and evict the device from the IOPF queue.","Type":"Description","Title":"iommu/vt-d: Fix iopf_refcount leak on RID domain replacement"}]}}}