CVE-2026-45894
Intel · VT-d
An improper IOMMU configuration in Intel VT-d allows for a race condition when tearing down PASID entries.
Executive summary
A high-severity vulnerability in Intel VT-d hardware virtualization can lead to memory corruption or potential privilege escalation.
Vulnerability
The vulnerability exists because the Present bit in the Intel VT-d Scalable Mode PASID table entry is not cleared before the entry is torn down. This leaves a window for invalid memory access.
Business impact
A CVSS score of 7.8 reflects the severity of this hardware-level memory management issue. Exploitation could allow an attacker to bypass virtualization protections, leading to cross-VM information disclosure or system-level compromise.
Remediation
Immediate Action: Apply the latest security patches for the Linux kernel that address Intel VT-d IOMMU management.
Proactive Monitoring: Monitor system health and virtualization logs for anomalies related to IOMMU or hardware-assisted virtualization.
Compensating Controls: Ensure that virtualization hosts are running fully patched firmware and kernels to maintain hardware isolation.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Organizations utilizing Intel-based virtualization should treat this as a high-priority update. Updating the kernel and firmware is critical to maintaining the security boundary between virtualized instances.