{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89451","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.706Z","datePublished":"2026-09-11T19:43:16.730Z","dateUpdated":"2026-09-11T19:43:16.730Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-11T19:43:16.730Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/sva: Set handle->dev before the SVA handle is visible\n\niommu_attach_device_pasid() installs the new SVA attach handle in the\ngroup PASID lookup before iommu_sva_bind_device() returns. A concurrent\nbind can therefore find and reuse the same handle after iommu_sva_lock is\ndropped.\n\nhandle->dev was initialized after dropping iommu_sva_lock. This leaves a\nwindow where a racing bind can return a handle whose dev pointer is still\nNULL. A subsequent iommu_sva_unbind_device() can then dereference it via\nhandle->dev->iommu_group.\n\nInitialize handle->dev before releasing iommu_sva_lock so any visible SVA\nhandle is fully initialized."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/iommu/iommu-sva.c"],"versions":[{"version":"be51b1d6bbff48c7d1943a8ff1e5a55777807f6e","lessThan":"bcffb1c75da8fc9d51168ff9f09d471c26507912","status":"affected","versionType":"git"},{"version":"be51b1d6bbff48c7d1943a8ff1e5a55777807f6e","lessThan":"968e9a1f71140c86dc4092f6b361e997923f3813","status":"affected","versionType":"git"},{"version":"be51b1d6bbff48c7d1943a8ff1e5a55777807f6e","lessThan":"37a96a30617a4c96f048a5874c00509bc4fe4d85","status":"affected","versionType":"git"},{"version":"be51b1d6bbff48c7d1943a8ff1e5a55777807f6e","lessThan":"530f8f9c3546cb3ebee1b135375aaee08a073ebb","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/iommu/iommu-sva.c"],"versions":[{"version":"6.2","status":"affected"},{"version":"0","lessThan":"6.2","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/bcffb1c75da8fc9d51168ff9f09d471c26507912"},{"url":"https://git.kernel.org/stable/c/968e9a1f71140c86dc4092f6b361e997923f3813"},{"url":"https://git.kernel.org/stable/c/37a96a30617a4c96f048a5874c00509bc4fe4d85"},{"url":"https://git.kernel.org/stable/c/530f8f9c3546cb3ebee1b135375aaee08a073ebb"}],"title":"iommu/sva: Set handle->dev before the SVA handle is visible","x_generator":{"engine":"bippy-1.2.0"}}}}