{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89452","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.706Z","datePublished":"2026-09-11T19:43:17.405Z","dateUpdated":"2026-10-03T10:56:29.062Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:56:29.062Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/msm: Unwind probe state on registration failure\n\nmsm_iommu_probe() adds its devm-managed IOMMU object to\nqcom_iommu_devices before adding the IOMMU sysfs device and registering\nit with the IOMMU core.\n\nIf iommu_device_sysfs_add() fails, probe returns with the object still on\nqcom_iommu_devices. The driver core then releases the devm allocation,\nleaving a dangling list entry that later list walks may dereference.\n\nIf iommu_device_register() fails, the same dangling list entry remains\nand the sysfs device is left registered as well.\n\nUnwind the sysfs device and global list entry in reverse setup order on\nthe corresponding failure paths."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is in msm_iommu_probe() for the Qualcomm APQ8064 platform IOMMU (compatible qcom,apq8064-iommu). It is reached only through the local platform driver core at boot or sysfs bind, not via network protocols, Bluetooth/WiFi, or a physical USB/serial endpoint.\nAC:L - After list_add, a failed iommu_device_sysfs_add() or iommu_device_register() deterministically leaves a freed msm_iommu_dev on qcom_iommu_devices. APQ8064 has four IOMMU instances, so a later probe, of_xlate, or attach walks that list and dereferences the object with no attacker-uncontrolled race. GFP_ATOMIC allocation in insert_iommu_master during register can induce the failure.\nPR:N - msm_iommu_probe() and later list walks in qcom_iommu_of_xlate(), find_iommu_for_dev(), and msm_iommu_attach_dev() run from the platform/IOMMU core with no capable() or credential check. On APQ8064 phones and embedded boards this happens automatically during boot or deferred probe without a user account.\nUI:N - Platform probe and subsequent IOMMU client attach/xlate run unattended during normal kernel device bring-up. No victim action such as mounting a filesystem, opening a file, or clicking a prompt is required.\nS:U - The use-after-free corrupts host kernel heap through the driver's private qcom_iommu_devices list, enabling in-kernel privilege escalation. It does not by itself escape a VM or bypass the IOMMU/DMA isolation boundary as a distinct security authority.\nC:H - The dangling msm_iommu_dev stays linked after devm frees it. Subsequent list walks dereference attacker-influencable freed heap (including embedded list pointers and device state), which per kernel UAF guidance enables arbitrary kernel memory disclosure.\nI:H - Use-after-free of the IOMMU instance structure (list nodes, MMIO base, context-bank maps) allows heap spraying and hijack of later attach/xlate control flow, providing an arbitrary kernel write and code-execution primitive.\nA:H - Any later walk of qcom_iommu_devices after the failed probe dereferences freed memory and can oops or panic the kernel. Kernel UAFs also crash even when not turned into a full exploit."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/iommu/msm_iommu.c"],"versions":[{"version":"42df43b36163ed7d0ab13992e411093252903273","lessThan":"51e37f9179387b6e3fa64a3d3b4fece1a38b3a02","status":"affected","versionType":"git"},{"version":"42df43b36163ed7d0ab13992e411093252903273","lessThan":"f532401be9312ecd166f616bb74a65b0b4c150fa","status":"affected","versionType":"git"},{"version":"42df43b36163ed7d0ab13992e411093252903273","lessThan":"7f7074a886c4a93e3d12076ce60a510a1ebe400c","status":"affected","versionType":"git"},{"version":"42df43b36163ed7d0ab13992e411093252903273","lessThan":"535a200220ca2c83bc8bf54bd2cbe045d6ee70c4","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/iommu/msm_iommu.c"],"versions":[{"version":"4.11","status":"affected"},{"version":"0","lessThan":"4.11","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.11","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.11","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.11","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.11","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/51e37f9179387b6e3fa64a3d3b4fece1a38b3a02"},{"url":"https://git.kernel.org/stable/c/f532401be9312ecd166f616bb74a65b0b4c150fa"},{"url":"https://git.kernel.org/stable/c/7f7074a886c4a93e3d12076ce60a510a1ebe400c"},{"url":"https://git.kernel.org/stable/c/535a200220ca2c83bc8bf54bd2cbe045d6ee70c4"}],"title":"iommu/msm: Unwind probe state on registration failure","x_generator":{"engine":"bippy-1.2.0"}}}}