Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-90242
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to leak an IOPF reference.
The vulnerability exists due to improper resource lifecycle management in the Intel VT-d IOMMU RID domain attachment paths when replacing a RID-level domain. A local user can replace a domain associated with a device to leak an IOPF reference.
The issue occurs when the replaced domain has an IOPF handler; the leaked reference prevents the device from being removed from the IOPF queue when released.