{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-52953","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-06-09T07:44:35.372Z","datePublished":"2026-06-24T16:28:36.110Z","dateUpdated":"2026-08-05T12:32:03.109Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:32:03.109Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Fix oops due to out of scope access\n\nBelow oops triggers when kill QEMU process:\n\n  Oops: general protection fault, probably for non-canonical address 0x7fffffff844eaaa7: 0000 [#1] SMP NOPTI\n  Call Trace:\n   <TASK>\n   do_raw_spin_lock+0xaa/0xc0\n   _raw_spin_lock_irqsave+0x21/0x40\n   domain_remove_dev_pasid+0x52/0x160\n   intel_nested_set_dev_pasid+0x1b9/0x1e0\n   __iommu_set_group_pasid+0x56/0x120\n   pci_dev_reset_iommu_done+0xe3/0x180\n   pcie_flr+0x65/0x160\n   __pci_reset_function_locked+0x5b/0x120\n   vfio_pci_core_close_device+0x63/0xe0 [vfio_pci_core]\n   vfio_df_close+0x4f/0xa0\n   vfio_df_unbind_iommufd+0x2d/0x60\n   vfio_device_fops_release+0x3e/0x40\n   __fput+0xe5/0x2c0\n   task_work_run+0x58/0xa0\n   do_exit+0x2c8/0x600\n   do_group_exit+0x2f/0xa0\n   get_signal+0x863/0x8c0\n   arch_do_signal_or_restart+0x24/0x100\n   exit_to_user_mode_loop+0x87/0x380\n   do_syscall_64+0x2ff/0x11e0\n   entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nThe global static blocked domain is a dummy domain without corresponding\ndmar_domain structure, accessing beyond iommu_domain structure triggers\noops easily. Fix it by return early in domain_remove_dev_pasid() like\nidentity domain."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","baseScore":7.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerable path is reached from local VFIO/iommufd device operations, such as a QEMU process closing or resetting an assigned PCI device with PASID state. It is not reachable by unauthenticated network traffic.\nAC:L - Once an Intel VT-d system with a PASID/ATS-capable VFIO PCI device is available, the trigger is deterministic: attach a PASID domain and close or reset the device. No race or condition outside attacker control is required.\nPR:L - The attacker needs local permission to open and operate the VFIO device and iommufd, but the relevant ioctls do not require real root after device access is granted. This is low privilege rather than unauthenticated access.\nUI:N - The attacker can trigger the bug by their own process closing/exiting or issuing device reset operations. No separate victim action is required.\nS:U - The impact is within the host kernel/IOMMU management context and does not demonstrate an IOMMU bypass or VM escape. Standard local kernel impact remains unchanged scope.\nC:N - The bug is an invalid out-of-object access that oopses in the spinlock path, with no data returned to the attacker. There is no demonstrated information disclosure primitive.\nI:H - The bad cast treats the static blocked domain as a larger Intel dmar_domain and performs spinlock/list-related accesses beyond the real object. This is kernel memory corruption, so under the higher-severity rule integrity impact is High.\nA:H - The commit documents a general protection fault/oops during QEMU teardown. A local attacker with VFIO device access can crash the kernel, causing high availability impact."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/iommu/intel/iommu.c"],"versions":[{"version":"7d0c9da6c1509664d96488042bacc02308ca33b2","lessThan":"88397fad7914ee74a7880fa5ce01f9eb6bfe0743","status":"affected","versionType":"git"},{"version":"7d0c9da6c1509664d96488042bacc02308ca33b2","lessThan":"1e659db468476733d217c1314c1e0d9244356d6c","status":"affected","versionType":"git"},{"version":"7d0c9da6c1509664d96488042bacc02308ca33b2","lessThan":"a6dea58d8625c06b9654c0555f101742481335c3","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/iommu/intel/iommu.c"],"versions":[{"version":"6.6","status":"affected"},{"version":"0","lessThan":"6.6","status":"unaffected","versionType":"semver"},{"version":"6.18.33","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.10","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"6.18.33"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"7.0.10"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/88397fad7914ee74a7880fa5ce01f9eb6bfe0743"},{"url":"https://git.kernel.org/stable/c/1e659db468476733d217c1314c1e0d9244356d6c"},{"url":"https://git.kernel.org/stable/c/a6dea58d8625c06b9654c0555f101742481335c3"}],"title":"iommu/vt-d: Fix oops due to out of scope access","x_generator":{"engine":"bippy-1.2.0"}}}}