Configuration in Linux kernel - CVE-2026-89448
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause access control services to remain disabled while the IOMMU is forced on.
The vulnerability exists due to improper configuration handling in detect_intel_iommu() when tboot forces the IOMMU on after ACS was not requested. A local privileged user can configure the system to disable ACS to cause access control services to remain disabled while the IOMMU is forced on.