{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89448","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.706Z","datePublished":"2026-09-11T19:43:14.746Z","dateUpdated":"2026-09-14T11:59:55.683Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T11:59:55.683Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Force requesting ACS when tboot is enabled\n\nCurrently the conditions of requesting ACS in detect_intel_iommu()\ndon't include tboot, leading to a possible misconfiguration with ACS\ndisabled (e.g. due to user opts) while iommu is later forced on by\ntboot_force_iommu().\n\nFix it by checking tboot in detect_intel_iommu()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":9.3,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:L - detect_intel_iommu() runs at boot from pci_iommu_alloc() and, when tboot later forces VT-d on, skips pci_request_acs(); a local PCIe/Thunderbolt DMA device or VFIO-passthrough guest can then spoof requester IDs and issue peer-to-peer DMA. This is not a network-protocol path.\nAC:L - On a tboot launch where intel_iommu=off, iommu=off, or default dmar_disabled skipped pci_request_acs(), ACS SV/RR/CR/UF/TB are never programmed; an attacker-controlled device can then deterministically perform P2P DMA or RID spoofing with no race or layout luck.\nPR:N - A malicious PCIe/Thunderbolt device or a tenant with an assigned passthrough/SR-IOV function issues the DMA itself and needs no host account, capability, or init-namespace root, matching other VT-d isolation-bypass scores for unauthenticated devices.\nUI:N - After the kernel boots with tboot-forced VT-d and ACS still disabled, the attacker’s device performs DMA on its own; no separate victim action such as mounting a filesystem or opening a file is required.\nS:C - Missing ACS lets a device spoof requester IDs and send peer-to-peer TLPs that never reach the IOMMU, crossing the device/host DMA isolation boundary that tboot forces VT-d on to enforce (IOMMU/DMA boundary bypass is Scope Changed).\nC:H - Without ACS source validation, request redirect, and translation blocking, a device can impersonate another requester ID or DMA to peer BARs, reading host or peer-device memory outside its IOMMU domain (arbitrary DMA disclosure).\nI:H - The same ACS gap yields DMA writes into host or peer-device memory, including ATS without translation blocking on external/untrusted ports, providing an arbitrary write primitive that can corrupt kernel memory and hijack control flow.\nA:H - Unchecked DMA writes and IOMMU-bypassing P2P traffic can corrupt kernel structures or provoke DMAR faults, oopses, and panics; any such host crash qualifies as High availability impact."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/iommu/intel/dmar.c","drivers/iommu/intel/iommu.c","drivers/iommu/intel/iommu.h"],"versions":[{"version":"5d990b627537e59a3a2f039ff588a4750e9c1a6a","lessThan":"579eb867d3da63f3b5e32f235925e1daa7ec70d0","status":"affected","versionType":"git"},{"version":"5d990b627537e59a3a2f039ff588a4750e9c1a6a","lessThan":"aaeb81241e802c86be69394f72d49fde3f861fbb","status":"affected","versionType":"git"},{"version":"5d990b627537e59a3a2f039ff588a4750e9c1a6a","lessThan":"45705a6bfdb283f7b3b509010fd617b72f942537","status":"affected","versionType":"git"},{"version":"5d990b627537e59a3a2f039ff588a4750e9c1a6a","lessThan":"87bc611c6c98a41c00feb7b06b0c297dd141a2ae","status":"affected","versionType":"git"},{"version":"5d990b627537e59a3a2f039ff588a4750e9c1a6a","lessThan":"607432b2618b61df81134be0ef2562b8300c1216","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/iommu/intel/dmar.c","drivers/iommu/intel/iommu.c","drivers/iommu/intel/iommu.h"],"versions":[{"version":"2.6.33","status":"affected"},{"version":"0","lessThan":"2.6.33","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.33","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.33","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.33","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.33","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.33","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/579eb867d3da63f3b5e32f235925e1daa7ec70d0"},{"url":"https://git.kernel.org/stable/c/aaeb81241e802c86be69394f72d49fde3f861fbb"},{"url":"https://git.kernel.org/stable/c/45705a6bfdb283f7b3b509010fd617b72f942537"},{"url":"https://git.kernel.org/stable/c/87bc611c6c98a41c00feb7b06b0c297dd141a2ae"},{"url":"https://git.kernel.org/stable/c/607432b2618b61df81134be0ef2562b8300c1216"}],"title":"iommu/vt-d: Force requesting ACS when tboot is enabled","x_generator":{"engine":"bippy-1.2.0"}}}}