Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: iommu: Fix WARN_ON in __iommu_group_set_domain_nofail() due to reset In… (CVE-2026-52952)
A vulnerability in the Linux kernel's IOMMU subsystem was fixed to address a use-after-free (UAF) condition triggered by improper handling of domain attachments during device recovery. The flaw involved the __iommu_group_set_domain_nofail() function, where concurrent domain attachments were incorrectly rejected, causing a WARN_ON and potential UAF when re-attaching the domain. This issue affects multiple Linux kernel versions prior to specific 7.0.0 releases and has been resolved in updated kernel packages. The vulnerability has a high CVSS score of 8.8, indicating significant confidentiality, integrity, and availability impacts, but no known exploits are reported in the wild. The fix is available through official Ubuntu kernel updates requiring a system reboot and recompilation of third-party kernel modules due to ABI changes.
AI Analysis
Technical Summary
CVE-2026-52952 is a Linux kernel vulnerability in the IOMMU subsystem related to the __iommu_group_set_domain_nofail() function. The flaw occurs because concurrent domain attachments are rejected during device recovery, which triggers a WARN_ON condition and leads to a use-after-free (UAF) when re-attaching the group domain. The fix involves honoring the IOMMU_SET_DOMAIN_MUST_SUCCEED flag to allow certain callers to update the group domain pointer properly, preventing the UAF. This vulnerability affects multiple Linux kernel versions prior to 7.0.0-28.28 and related builds. The issue is addressed in official Ubuntu kernel updates, which require a reboot and recompilation of third-party kernel modules due to an ABI change.
Potential Impact
Successful exploitation of this vulnerability could lead to a use-after-free condition in the Linux kernel IOMMU subsystem, potentially allowing local attackers with limited privileges to escalate their privileges and compromise system confidentiality, integrity, and availability. The CVSS 3.1 score is 8.8 (high severity), reflecting local attack vector with low complexity, no user interaction, and complete impact on confidentiality, integrity, and availability. No known exploits are currently reported in the wild.
Mitigation Recommendations
An official fix is available and included in updated Linux kernel packages for Ubuntu 26.04 LTS and related releases. Users should apply the kernel updates to versions 7.0.0-28.28 or later as specified in the vendor advisory. A system reboot is required to apply the changes. Due to an ABI change, recompilation and reinstallation of all third-party kernel modules are necessary after the update. Follow the vendor's update instructions carefully to ensure full remediation.
Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: iommu: Fix WARN_ON in __iommu_group_set_domain_nofail() due to reset In… (CVE-2026-52952)
Description
A vulnerability in the Linux kernel's IOMMU subsystem was fixed to address a use-after-free (UAF) condition triggered by improper handling of domain attachments during device recovery. The flaw involved the __iommu_group_set_domain_nofail() function, where concurrent domain attachments were incorrectly rejected, causing a WARN_ON and potential UAF when re-attaching the domain. This issue affects multiple Linux kernel versions prior to specific 7.0.0 releases and has been resolved in updated kernel packages. The vulnerability has a high CVSS score of 8.8, indicating significant confidentiality, integrity, and availability impacts, but no known exploits are reported in the wild. The fix is available through official Ubuntu kernel updates requiring a system reboot and recompilation of third-party kernel modules due to ABI changes.
CVSS v3.1
Score 8.8high
Affected software
pkg:deb/ubuntu/[email protected]~16.04.1?arch=source&distro=xenialpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]~18.04.2?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]~18.04.1?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]~18.04.1?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]~18.04.1?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]~18.04.2?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]~18.04.1?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.2?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]+cvm1.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.3?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.2?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.2.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=bluefield/noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=realtime/noblepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-52952 is a Linux kernel vulnerability in the IOMMU subsystem related to the __iommu_group_set_domain_nofail() function. The flaw occurs because concurrent domain attachments are rejected during device recovery, which triggers a WARN_ON condition and leads to a use-after-free (UAF) when re-attaching the group domain. The fix involves honoring the IOMMU_SET_DOMAIN_MUST_SUCCEED flag to allow certain callers to update the group domain pointer properly, preventing the UAF. This vulnerability affects multiple Linux kernel versions prior to 7.0.0-28.28 and related builds. The issue is addressed in official Ubuntu kernel updates, which require a reboot and recompilation of third-party kernel modules due to an ABI change.
Potential Impact
Successful exploitation of this vulnerability could lead to a use-after-free condition in the Linux kernel IOMMU subsystem, potentially allowing local attackers with limited privileges to escalate their privileges and compromise system confidentiality, integrity, and availability. The CVSS 3.1 score is 8.8 (high severity), reflecting local attack vector with low complexity, no user interaction, and complete impact on confidentiality, integrity, and availability. No known exploits are currently reported in the wild.
Mitigation Recommendations
An official fix is available and included in updated Linux kernel packages for Ubuntu 26.04 LTS and related releases. Users should apply the kernel updates to versions 7.0.0-28.28 or later as specified in the vendor advisory. A system reboot is required to apply the changes. Due to an ABI change, recompilation and reinstallation of all third-party kernel modules are necessary after the update. Follow the vendor's update instructions carefully to ensure full remediation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-52952
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:16.04:LTS","Ubuntu:18.04:LTS","Ubuntu:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:Nvidia-BlueField:24.04:LTS","Ubuntu:Pro:Realtime:24.04:LTS","Ubuntu:26.04:LTS"]
- Cvss Version
- 3.1
Threat ID: 6a5a016b91ae9bcd3f802c4e
Added to database: 07/17/2026, 10:18:19 UTC
Last enriched: 09/07/2026, 23:33:23 UTC
Last updated: 09/10/2026, 19:36:54 UTC
Views: 19
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.