{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-26786","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-02-19T14:20:24.178Z","datePublished":"2024-04-04T08:20:19.109Z","dateUpdated":"2026-08-05T11:27:14.106Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:27:14.106Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niommufd: Fix iopt_access_list_id overwrite bug\n\nSyzkaller reported the following WARN_ON:\n  WARNING: CPU: 1 PID: 4738 at drivers/iommu/iommufd/io_pagetable.c:1360\n\n  Call Trace:\n   iommufd_access_change_ioas+0x2fe/0x4e0\n   iommufd_access_destroy_object+0x50/0xb0\n   iommufd_object_remove+0x2a3/0x490\n   iommufd_object_destroy_user\n   iommufd_access_destroy+0x71/0xb0\n   iommufd_test_staccess_release+0x89/0xd0\n   __fput+0x272/0xb50\n   __fput_sync+0x4b/0x60\n   __do_sys_close\n   __se_sys_close\n   __x64_sys_close+0x8b/0x110\n   do_syscall_x64\n\nThe mismatch between the access pointer in the list and the passed-in\npointer is resulting from an overwrite of access->iopt_access_list_id, in\niopt_add_access(). Called from iommufd_access_change_ioas() when\nxa_alloc() succeeds but iopt_calculate_iova_alignment() fails.\n\nAdd a new_id in iopt_add_access() and only update iopt_access_list_id when\nreturning successfully."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached only through ioctls on local character devices — `/dev/iommu` or `/dev/vfio/vfio` (`IOMMU_IOAS_MAP`/`IOMMU_IOAS_UNMAP`) plus `VFIO_DEVICE_ATTACH_IOMMUFD_PT` on an emulated VFIO device fd. No network or adjacent-network path exists.\nAC:L - The failure is fully deterministic and attacker-scripted: a fresh IOAS has `iova_alignment = 1`, so mapping at an unaligned IOVA guarantees `iopt_calculate_iova_alignment()` returns `-EADDRINUSE` when an access with `needs_pin_pages` is attached, and `xa_alloc()` hands out the lowest free index so the id collision is predictable. No race and no uncontrolled memory layout are involved.\nPR:L - iommufd performs no capability check on open or on any ioctl; access is gated only by device-node permissions, and `/dev/vfio/vfio` is registered with `.mode = 0666` while `/dev/iommu` is routinely granted to the unprivileged VMM/qemu user that owns mdev devices. An ordinary local user in a virtualization deployment can drive the entire sequence without root.\nUI:N - The attacker performs every step — IOAS allocation, the unaligned map, the failing attach/replace, and the destroy that leaves the dangling entry — entirely within its own process. No victim action is required.\nS:U - The corrupted state and the resulting memory corruption both live in kernel memory under the same security authority as the attacking local process. The page pins held by the stale access prevent an actual DMA/IOMMU isolation escape, so no security boundary is crossed.\nC:H - The freed `struct iommufd_access` remains linked in `iopt->access_list` and is dereferenced by `iopt_calculate_iova_alignment()` and `iommufd_access_notify_unmap()`; controlling the reclaimed slab object turns this use-after-free into an arbitrary kernel-memory read primitive.\nI:H - `iommufd_access_notify_unmap()` performs `access->ops->unmap(access->data, ...)` — an indirect call through a function-pointer table read from freed, sprayable `GFP_KERNEL_ACCOUNT` memory with an attacker-chosen first argument — plus a refcount increment into the freed object, yielding control-flow hijack and arbitrary write.\nA:H - The mismatch trips `WARN_ON()` in `iopt_remove_access()` (fatal under `panic_on_warn`), the use-after-free readily oopses, and a silently unlinked access drives `iopt_unmap_iova_range()` through its 100-retry loop to `WARN_ON` + `-EDEADLOCK`, permanently wedging unmap on that IOAS."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/iommu/iommufd/io_pagetable.c"],"versions":[{"version":"9227da7816dd1a42e20d41e2244cb63c205477ca","lessThan":"f1fb745ee0a6fe43f1d84ec369c7e6af2310fda9","status":"affected","versionType":"git"},{"version":"9227da7816dd1a42e20d41e2244cb63c205477ca","lessThan":"9526a46cc0c378d381560279bea9aa34c84298a0","status":"affected","versionType":"git"},{"version":"9227da7816dd1a42e20d41e2244cb63c205477ca","lessThan":"aeb004c0cd6958e910123a1607634401009c9539","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/iommu/iommufd/io_pagetable.c"],"versions":[{"version":"6.6","status":"affected"},{"version":"0","lessThan":"6.6","status":"unaffected","versionType":"semver"},{"version":"6.6.21","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.7.9","lessThanOrEqual":"6.7.*","status":"unaffected","versionType":"semver"},{"version":"6.8","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"6.6.21"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"6.7.9"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"6.8"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/f1fb745ee0a6fe43f1d84ec369c7e6af2310fda9"},{"url":"https://git.kernel.org/stable/c/9526a46cc0c378d381560279bea9aa34c84298a0"},{"url":"https://git.kernel.org/stable/c/aeb004c0cd6958e910123a1607634401009c9539"}],"title":"iommufd: Fix iopt_access_list_id overwrite bug","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-476","lang":"en","description":"CWE-476 NULL Pointer Dereference"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":5.5,"attackVector":"LOCAL","baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"LOW","confidentialityImpact":"NONE"}},{"other":{"type":"ssvc","content":{"timestamp":"2024-07-15T16:04:45.617050Z","id":"CVE-2024-26786","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-11-04T16:19:48.130Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T00:14:13.526Z"},"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/f1fb745ee0a6fe43f1d84ec369c7e6af2310fda9","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/9526a46cc0c378d381560279bea9aa34c84298a0","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/aeb004c0cd6958e910123a1607634401009c9539","tags":["x_transferred"]}]}]}}