iommu: disable SVA when CONFIG_X86 is set
Published Jan 13, 2026
7.8
HIGHCVSS 3.1
EPSS 0.17%
Description
Patch series "Fix stale IOTLB entries for kernel address space", v7.
This proposes a fix for a security vulnerability related to IOMMU Shared Virtual Addressing (SVA). In an SVA context, an IOMMU can cache kernel page table entries. When a kernel page table page is freed and reallocated for another purpose, the IOMMU might still hold stale, incorrect entries. This can be exploited to cause a use-after-free or write-after-free condition, potentially leading to privilege escalation or data corruption.
This solution introduces a deferred freeing mechanism for kernel page table pages, which provides a safe window to notify the IOMMU to invalidate its caches before the page is reused.
This patch (of 8):
In the IOMMU Shared Virtual Addressing (SVA) context, the IOMMU hardware shares and walks the CPU's page tables. The x86 architecture maps the kernel's virtual address space into the upper portion of every process's page table. Consequently, in an SVA context, the IOMMU hardware can walk and cache kernel page table entries.
The Linux kernel currently lacks a notification mechanism for kernel page table changes, specifically when page table pages are freed and reused. The IOMMU driver is only notified of changes to user virtual address mappings. This can cause the IOMMU's internal caches to retain stale entries for kernel VA.
Use-After-Free (UAF) and Write-After-Free (WAF) conditions arise when kernel page table pages are freed and later reallocated. The IOMMU could misinterpret the new data as valid page table entries. The IOMMU might then walk into attacker-controlled memory, leading to arbitrary physical memory DMA access or privilege escalation. This is also a Write-After-Free issue, as the IOMMU will potentially continue to write Accessed and Dirty bits to the freed memory while attempting to walk the stale page tables.
Currently, SVA contexts are unprivileged and cannot access kernel mappings. However, the IOMMU will still walk kernel-only page tables all the way down to the leaf entries, where it realizes the mapping is for the kernel and errors out. This means the IOMMU still caches these intermediate page table entries, making the described vulnerability a real concern.
Disable SVA on x86 architecture until the IOMMU can receive notification to flush the paging cache before freeing the CPU kernel page table pages.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.2StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.2
- Version 5.15.200StatusunaffectedConstraints<=5.15.*
- Version 6.1.163StatusunaffectedConstraints<=6.1.*
- Version 6.12.64StatusunaffectedConstraints<=6.12.*
- Version 6.18.4StatusunaffectedConstraints<=6.18.*
- Version 6.19StatusunaffectedConstraints<=*
- Version 6.6.120StatusunaffectedConstraints<=6.6.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 5.2 · < 5.15.200
- ≥ 5.16 · < 6.1.163
- ≥ 6.2 · < 6.6.120
- ≥ 6.7 · < 6.12.64
- ≥ 6.13 · < 6.18.4
No data.
Red Hat Enterprise Linux 10.0 Extended Update Support
kernel-0:6.12.0-55.98.1.el10_0
Fixed · RHSA-2026:55445
Red Hat Enterprise Linux 8
kernel-0:4.18.0-553.143.1.el8_10
Fixed · RHSA-2026:39083
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-553.143.1.rt7.484.el8_10
Fixed · RHSA-2026:39082
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
kernel-0:4.18.0-305.194.1.el8_4
Fixed · RHSA-2026:26535
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
kernel-0:4.18.0-305.194.1.el8_4
Fixed · RHSA-2026:26535
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
kernel-0:4.18.0-372.195.1.el8_6
Fixed · RHSA-2026:25533
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
kernel-0:4.18.0-372.195.1.el8_6
Fixed · RHSA-2026:25533
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
kernel-0:4.18.0-477.147.1.el8_8
Fixed · RHSA-2026:26563
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
kernel-0:4.18.0-477.147.1.el8_8
Fixed · RHSA-2026:26563
Red Hat Enterprise Linux 9
kernel-0:5.14.0-687.12.1.el9_8
Fixed · RHSA-2026:21556
Red Hat Enterprise Linux 9
kernel-0:5.14.0-687.12.1.el9_8
Fixed · RHSA-2026:21556
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
kernel-0:5.14.0-284.176.1.el9_2
Fixed · RHSA-2026:26515
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
kernel-rt-0:5.14.0-284.176.1.rt14.461.el9_2
Fixed · RHSA-2026:26462
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
kernel-0:5.14.0-427.129.1.el9_4
Fixed · RHSA-2026:23237
Red Hat Enterprise Linux 9.6 Extended Update Support
kernel-0:5.14.0-570.120.1.el9_6
Fixed · RHSA-2026:25218
Red Hat Enterprise Linux 10
kernel
Affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10.0 Extended Update Support | kernel-0:6.12.0-55.98.1.el10_0 | Fixed | RHSA-2026:55445 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-553.143.1.el8_10 | Fixed | RHSA-2026:39083 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-553.143.1.rt7.484.el8_10 | Fixed | RHSA-2026:39082 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | kernel-0:4.18.0-305.194.1.el8_4 | Fixed | RHSA-2026:26535 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | kernel-0:4.18.0-305.194.1.el8_4 | Fixed | RHSA-2026:26535 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | kernel-0:4.18.0-372.195.1.el8_6 | Fixed | RHSA-2026:25533 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | kernel-0:4.18.0-372.195.1.el8_6 | Fixed | RHSA-2026:25533 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | kernel-0:4.18.0-477.147.1.el8_8 | Fixed | RHSA-2026:26563 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | kernel-0:4.18.0-477.147.1.el8_8 | Fixed | RHSA-2026:26563 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-687.12.1.el9_8 | Fixed | RHSA-2026:21556 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-687.12.1.el9_8 | Fixed | RHSA-2026:21556 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | kernel-0:5.14.0-284.176.1.el9_2 | Fixed | RHSA-2026:26515 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | kernel-rt-0:5.14.0-284.176.1.rt14.461.el9_2 | Fixed | RHSA-2026:26462 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | kernel-0:5.14.0-427.129.1.el9_4 | Fixed | RHSA-2026:23237 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | kernel-0:5.14.0-570.120.1.el9_6 | Fixed | RHSA-2026:25218 |
| Red Hat Enterprise Linux 10 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This is a significant security vulnerability affecting x86 systems with IOMMU SVA support enabled. While SVA contexts are unprivileged and cannot directly access kernel mappings, the IOMMU still walks and caches intermediate kernel page table entries. An attacker could potentially exploit the stale cache entries to gain arbitrary DMA access or escalate privileges. The fix disables SVA on x86 until proper cache invalidation mechanisms are implemented.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
2 other sources (CVE.org, Red Hat) ▾
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Jun 16, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Jan–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.17% (0.00165) | 5.08th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.14% (0.00145) | 4.08th | v5 (v2026.06.15) |
| Jan 14, 2026 | 0.02% (0.00018) | 3.68th | v4 (v2025.03.14) |
References (11)
- https://access.redhat.com/security/cve/CVE-2025-71089 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2429104 Issue Tracking
- https://git.kernel.org/stable/c/240cd7f2812cc25496b12063d11c823618f364e9 Patch
- https://git.kernel.org/stable/c/72f98ef9a4be30d2a60136dd6faee376f780d06c Patch
- https://git.kernel.org/stable/c/7cad37e358970af1bb49030ff01f06a69fa7d985 Patch
- https://git.kernel.org/stable/c/b34289505180a83607fcfdce14b5a290d0528476 Patch
- https://git.kernel.org/stable/c/c2c3f1a3fd74ef16cf115f0c558616a13a8471b4 Patch
- https://git.kernel.org/stable/c/c341dee80b5df49a936182341b36395c831c2661 Patch
- https://lore.kernel.org/linux-cve-announce/2026011341-CVE-2025-71089-a642@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-71089
- https://www.cve.org/CVERecord?id=CVE-2025-71089
Change history (0)
No recorded changes yet.