Bug 2517030 (CVE-2026-74520)
| Summary: | CVE-2026-74520 kernel: iommu/iommufd: Fix IOPF group ownership UAF | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the Linux kernel's IOMMU (Input/Output Memory Management Unit) and IOMMUFD (IOMMU File Descriptor) components. This vulnerability is a Use-After-Free (UAF), which means the system attempts to use memory that has already been released. Specifically, during device detachment or hardware page table replacement, an IOMMU Page Fault (IOPF) group can be freed while still being referenced by other parts of the system. An attacker could potentially exploit this to cause system instability, crashes, or achieve privilege escalation.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-08-15 12:45:31 UTC
|