CVE-2026-23429

In the Linux kernel, the following vulnerability has been resolved: iommu/sva: Fix crash in iommu_sva_unbind_device() domain->mm->iommu_mm can be freed by iommu_domain_free(): iommu_domain_free() mmdrop() __mmdrop() mm_pasid_drop() After iommu_domain_free() returns, accessing domain->mm->iommu_mm may dereference a freed mm structure, leading to a crash. Fix this by moving the code that accesses domain->mm->iommu_mm to before the call to iommu_domain_free().
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*

History

24 Jul 2026, 21:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: iommu/sva: Corrige un fallo en iommu_sva_unbind_device() domain -> mm -> iommu_mm puede ser liberado por iommu_domain_free(): iommu_domain_free() mmdrop() __mmdrop() mm_pasid_drop() Después de que iommu_domain_free() retorna, acceder a domain -> mm -> iommu_mm puede desreferenciar una estructura mm liberada, lo que lleva a un fallo. Soluciona esto moviendo el código que accede a domain -> mm -> iommu_mm a antes de la llamada a iommu_domain_free().

27 Apr 2026, 14:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.5
v2 : unknown
v3 : 7.8

23 Apr 2026, 21:03

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*
First Time Linux
Linux linux Kernel
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE NVD-CWE-noinfo
References () https://git.kernel.org/stable/c/06e14c36e20b48171df13d51b89fe67c594ed07a - () https://git.kernel.org/stable/c/06e14c36e20b48171df13d51b89fe67c594ed07a - Patch
References () https://git.kernel.org/stable/c/58abeb7b9562f25bdfa2f5ae5ce803eb02e74433 - () https://git.kernel.org/stable/c/58abeb7b9562f25bdfa2f5ae5ce803eb02e74433 - Patch
References () https://git.kernel.org/stable/c/f5daaa2c959d9f894fb5b1ab76da8612dd220a0d - () https://git.kernel.org/stable/c/f5daaa2c959d9f894fb5b1ab76da8612dd220a0d - Patch

03 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 16:16

Updated : 2026-07-24 21:10


NVD link : CVE-2026-23429

Mitre link : CVE-2026-23429

CVE.ORG link : CVE-2026-23429


JSON object : View

Products Affected

linux

  • linux_kernel