CVE-2026-45945
published 2026-05-27CVE-2026-45945: In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix race condition during PASID entry replacement The Intel VT-d PASID table…
PriorityP343high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.13%
3.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
iommu/vt-d: Fix race condition during PASID entry replacement
The Intel VT-d PASID table entry is 512 bits (64 bytes). When replacing
an active PASID entry (e.g., during domain replacement), the current
implementation calculates a new entry on the stack and copies it to the
table using a single structure assignment.
struct pasid_entry *pte, new_pte;
pte = intel_pasid_get_entry(dev, pasid);
pasid_pte_config_first_level(iommu, &new_pte, ...);
*pte = new_pte;
Because the hardware may fetch the 512-bit PASID entry in multiple
128-bit chunks, updating the entire entry while it is active (Present
bit set) risks a "torn" read. In this scenario, the IOMMU hardware
could observe an inconsistent state — partially new data and partially
old data — leading to unpredictable behavior or spurious faults.
Fix this by removing the unsafe "replace" helpers and following the
"clear-then-update" flow, which ensures the Present bit is cleared and
the required invalidation handshake is completed before the new
configuration is applied.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= 7543ee63e8113aa34b07df3b16b3b9d2c5f73939 < 4718007870547e1efebbdd6745d9fce58f008fef | 4718007870547e1efebbdd6745d9fce58f008fef |
| linux | linux | >= 7543ee63e8113aa34b07df3b16b3b9d2c5f73939 < 66a7aff480a82b8642b3991fed5fdc9780022157 | 66a7aff480a82b8642b3991fed5fdc9780022157 |
| linux | linux | >= 7543ee63e8113aa34b07df3b16b3b9d2c5f73939 < c3b1edea3791fa91ab7032faa90355913ad9451b | c3b1edea3791fa91ab7032faa90355913ad9451b |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 6.13 < 6.19.4 | 6.19.4 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3f6r-v6w8-rw99: In the Linux kernel, the following vulnerability has been resolved:
iommu/vt-d: Fix race condition during PASID entry replacement
The Intel VT-d PAS
ghsa_unreviewed·2026-05-27
CVE-2026-45945 GHSA-3f6r-v6w8-rw99: In the Linux kernel, the following vulnerability has been resolved:
iommu/vt-d: Fix race condition during PASID entry replacement
The Intel VT-d PAS
In the Linux kernel, the following vulnerability has been resolved:
iommu/vt-d: Fix race condition during PASID entry replacement
The Intel VT-d PASID table entry is 512 bits (64 bytes). When replacing
an active PASID entry (e.g., during domain replacement), the current
implementation calculates a new entry on the stack and copies it to the
table using a single structure assignment.
struct pasid_entry *pte, new_pte;
pte = intel_pasid_get_entry(dev, pasid);
pasid_pte_config_first_level(iommu, &new_pte, ...);
*pte = new_pte;
Because the hardware may fetch the 512-bit PASID entry in multiple
128-bit chunks, updating the entire entry while it is active (Present
bit set) risks a "torn" read. In this scenario, the IOMMU hardware
could observe an inconsistent state — partially new data and p
Red Hat
kernel: iommu/vt-d: Fix race condition during PASID entry replacement
vendor_redhat·2026-05-27·CVSS 5.5
CVE-2026-45945 [MEDIUM] CWE-366 kernel: iommu/vt-d: Fix race condition during PASID entry replacement
kernel: iommu/vt-d: Fix race condition during PASID entry replacement
A flaw was found in the Linux kernel's Intel VT-d (Virtualization Technology for Directed I/O) implementation. A race condition occurs during the replacement of an active PASID (Process Address Space ID) entry. This can lead to the IOMMU (Input/Output Memory Management Unit) hardware reading an inconsistent state, resulting in unpredictable system behavior or spurious faults, effectively causing a Denial of Service.
Package: kernel (Red Hat Enterprise Linux 10) - Fix deferred
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
No detection rules found.
No public exploits indexed.
2026-05-27
Published