In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix UAF in selftest IOPF reporting IOMMUFD selftest TRIGGER_IOPF… (CVE-2026-89445)
A use-after-free (UAF) vulnerability in the Linux kernel's iommufd selftest IOPF reporting component has been fixed. The flaw occurs when a borrowed attach handle is dereferenced after it has been freed due to a concurrent detach operation, leading to potential memory corruption. The fix involves adding synchronization via a read-write semaphore to properly coordinate access to attach handles during device fault reporting and domain attachment/detachment.
AI Analysis
Technical Summary
CVE-2026-89445 addresses a use-after-free vulnerability in the Linux kernel's iommufd selftest IOPF reporting. The issue arises because the TRIGGER_IOPF test borrows an attach handle from group->pasid_array without synchronizing against PASID detach operations. Concurrent calls to iommu_report_device_fault() can dereference a domain pointer from a freed attach handle, causing a UAF. The patch adds a read-write semaphore (iopf_rwsem) in the mock device driver to synchronize access, holding the read lock during iommu_report_device_fault() and the write lock during attach, detach, or replacement of device domains, preventing access to freed memory.
Potential Impact
The vulnerability could lead to use-after-free memory corruption in the Linux kernel, potentially causing system instability or crashes. No information about exploitation in the wild is available.
Mitigation Recommendations
A fix has been implemented in the Linux kernel by adding proper synchronization using a read-write semaphore to prevent use-after-free conditions. Users should apply the official kernel update containing this patch once available. No alternative mitigations are indicated.
In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix UAF in selftest IOPF reporting IOMMUFD selftest TRIGGER_IOPF… (CVE-2026-89445)
Description
A use-after-free (UAF) vulnerability in the Linux kernel's iommufd selftest IOPF reporting component has been fixed. The flaw occurs when a borrowed attach handle is dereferenced after it has been freed due to a concurrent detach operation, leading to potential memory corruption. The fix involves adding synchronization via a read-write semaphore to properly coordinate access to attach handles during device fault reporting and domain attachment/detachment.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-89445 addresses a use-after-free vulnerability in the Linux kernel's iommufd selftest IOPF reporting. The issue arises because the TRIGGER_IOPF test borrows an attach handle from group->pasid_array without synchronizing against PASID detach operations. Concurrent calls to iommu_report_device_fault() can dereference a domain pointer from a freed attach handle, causing a UAF. The patch adds a read-write semaphore (iopf_rwsem) in the mock device driver to synchronize access, holding the read lock during iommu_report_device_fault() and the write lock during attach, detach, or replacement of device domains, preventing access to freed memory.
Potential Impact
The vulnerability could lead to use-after-free memory corruption in the Linux kernel, potentially causing system instability or crashes. No information about exploitation in the wild is available.
Mitigation Recommendations
A fix has been implemented in the Linux kernel by adding proper synchronization using a read-write semaphore to prevent use-after-free conditions. Users should apply the official kernel update containing this patch once available. No alternative mitigations are indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-52p7-c9pg-r5j6
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-89445"]
Threat ID: 6aa4a02755bf5e2cf5a86b07
Added to database: 09/12/2026, 00:43:19 UTC
Last enriched: 09/12/2026, 01:19:16 UTC
Last updated: 09/12/2026, 01:19:16 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.