{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90388","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.810Z","datePublished":"2026-09-17T16:09:23.140Z","dateUpdated":"2026-09-18T17:55:02.646Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:55:02.646Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/dma: Check atomic pool allocation result directly\n\nThe non-blocking, non-coherent allocation path uses dma_alloc_from_pool(),\nwhich returns the allocated page and fills cpu_addr only on success.\n\nDo not rely on cpu_addr to detect allocation failure in this path. Check\nthe returned page directly before using it for the IOMMU mapping."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - iommu_dma_alloc() is reached from dma_alloc_attrs() on GFP_ATOMIC dma_alloc_coherent(); local entry points are VIDIOC_STREAMON scheduling mxc_jpeg_device_run()→mxc_jpeg_alloc(), and USBDEVFS_SUBMITURB in proc_do_submiturb()→usb_submit_urb(GFP_ATOMIC)→dma_pool_alloc()→pool_alloc_page(). No remote protocol message supplies the failed allocation.\nAC:L - The attacker drives dma_alloc_from_pool() failure by consuming the atomic gen_pool (repeated GFP_ATOMIC coherent allocs or a size larger than gen_pool_avail) then issues that ioctl; __dma_alloc_from_pool() does not store cpu_addr on failure, so a non-NULL leftover skips the old !cpu_addr check with no victim-side race.\nPR:L - mxc_jpeg_open() and proc_do_submiturb() have no capable() check; an unprivileged local user who can open the JPEG /dev/videoN or a usbfs device node reaches iommu_dma_alloc() without init-namespace root.\nUI:N - The attacker itself issues VIDIOC_QBUF/VIDIOC_STREAMON on its video fd or USBDEVFS_SUBMITURB on its usbfs fd; no separate user must mount, confirm, or plug a device.\nS:U - The leftover cpu_addr is used as a host kernel VA and page_to_phys(NULL) is mapped only in this device's iommu_dma domain via __iommu_dma_map(); that is in-kernel corruption, not a KVM/Xen escape or an extra translation into another VM's memory.\nC:H - iommu_dma_alloc() returns the uninitialized cpu_addr as the coherent buffer; later loads of that object (mxc_jpeg_config_dec_desc()/print_descriptor_info on slot_data.desc, or USB TD completion from a dma_pool block carved out of the wild page) disclose kernel memory through the leftover pointer.\nI:H - Callers store through that pointer: mxc_jpeg_config_dec_desc() writes desc->imgsize/stm_ctrl into jpeg->slot_data.desc, and pool_initialise_page() writes dma_block.next_block into page->vaddr from the failed dma_alloc_from_pool(), a kernel write primitive.\nA:H - page_to_phys(NULL) followed by iommu_map() in __iommu_dma_map(), or a store/load through an unmapped leftover cpu_addr in mxc_jpeg_config_dec_desc() or pool_initialise_page(), oopses or panics the kernel."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/iommu/dma-iommu.c"],"versions":[{"version":"9420139f516d7fbc248ce17f35275cb005ed98ea","lessThan":"ac9cd0a669b8be5d178dbd471b0d68039dac58b5","status":"affected","versionType":"git"},{"version":"9420139f516d7fbc248ce17f35275cb005ed98ea","lessThan":"db46cb9da83a507d86d2bb080bdb09c865da3d0a","status":"affected","versionType":"git"},{"version":"9420139f516d7fbc248ce17f35275cb005ed98ea","lessThan":"d56c3f955b21e5764c1497e295a5b5d0b3a40470","status":"affected","versionType":"git"},{"version":"9420139f516d7fbc248ce17f35275cb005ed98ea","lessThan":"06dffc96693083dda3412311406e558cf27f1574","status":"affected","versionType":"git"},{"version":"9420139f516d7fbc248ce17f35275cb005ed98ea","lessThan":"a4ace31d732b657d774e31fb444c0c27d42c78e5","status":"affected","versionType":"git"},{"version":"9420139f516d7fbc248ce17f35275cb005ed98ea","lessThan":"fb0b39287ba894dbdfac2901c51788b63f5c2291","status":"affected","versionType":"git"},{"version":"9420139f516d7fbc248ce17f35275cb005ed98ea","lessThan":"8c486293ddd0af60991408149fc3e964ea888dc4","status":"affected","versionType":"git"},{"version":"9420139f516d7fbc248ce17f35275cb005ed98ea","lessThan":"af95a0ebc0a0db0762be75f51eadf770bad01aaa","status":"affected","versionType":"git"},{"version":"47184b9ddf184cc9a77cf441943a0fe9b7afa575","status":"affected","versionType":"git"},{"version":"5.8.6","lessThan":"5.9","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/iommu/dma-iommu.c"],"versions":[{"version":"5.9","status":"affected"},{"version":"0","lessThan":"5.9","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.9","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.9","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.9","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.9","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.9","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.9","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.9","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.9","versionEndExcluding":"7.3-rc1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8.6"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/ac9cd0a669b8be5d178dbd471b0d68039dac58b5"},{"url":"https://git.kernel.org/stable/c/db46cb9da83a507d86d2bb080bdb09c865da3d0a"},{"url":"https://git.kernel.org/stable/c/d56c3f955b21e5764c1497e295a5b5d0b3a40470"},{"url":"https://git.kernel.org/stable/c/06dffc96693083dda3412311406e558cf27f1574"},{"url":"https://git.kernel.org/stable/c/a4ace31d732b657d774e31fb444c0c27d42c78e5"},{"url":"https://git.kernel.org/stable/c/fb0b39287ba894dbdfac2901c51788b63f5c2291"},{"url":"https://git.kernel.org/stable/c/8c486293ddd0af60991408149fc3e964ea888dc4"},{"url":"https://git.kernel.org/stable/c/af95a0ebc0a0db0762be75f51eadf770bad01aaa"}],"title":"iommu/dma: Check atomic pool allocation result directly","x_generator":{"engine":"bippy-1.2.0"}}}}