Function Call with Incorrectly Specified Arguments in Linux kernel - CVE-2026-80894

 

Function Call with Incorrectly Specified Arguments in Linux kernel - CVE-2026-80894

Published: September 5, 2026


Vulnerability identifier: #VU147025
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80894
CWE-ID: CWE-628
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to prevent automatic responses to IOMMU faults.

The vulnerability exists due to incorrectly specified function arguments in iommufd_hwpt_replace_device() when replacing a device hardware page table. A local user can replace a device hardware page table while faults are pending to prevent automatic responses to IOMMU faults.

The affected fault group is associated with the hardware page table that was attached when fault delivery occurred.


Affected software

Linux kernel

How to mitigate CVE-2026-80894

Install security update from vendor's repository.


External References

Related Security Bulletins