SB20260816191 - Use-after-free in Linux kernel IOMMUFD IOPF group handling logic



SB20260816191 - Use-after-free in Linux kernel IOMMUFD IOPF group handling logic

Published: August 16, 2026

Security Bulletin ID SB20260816191
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Use-after-free (CVE-ID: CVE-2026-74520)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the IOMMUFD IOPF group handling logic when processing page fault groups during device detach or HWPT replacement. A local user can trigger fault handling and later access a freed group to cause a denial of service.

The issue occurs because an accepted group can remain referenced by the IOMMUFD deliver list or response xarray after being freed through the generic pending list.


Remediation

Install update from vendor's website.