CVE-2026-45894

Intel · VT-d

An improper IOMMU configuration in Intel VT-d allows for a race condition when tearing down PASID entries.

Executive summary

A high-severity vulnerability in Intel VT-d hardware virtualization can lead to memory corruption or potential privilege escalation.

Vulnerability

The vulnerability exists because the Present bit in the Intel VT-d Scalable Mode PASID table entry is not cleared before the entry is torn down. This leaves a window for invalid memory access.

Business impact

A CVSS score of 7.8 reflects the severity of this hardware-level memory management issue. Exploitation could allow an attacker to bypass virtualization protections, leading to cross-VM information disclosure or system-level compromise.

Remediation

Immediate Action: Apply the latest security patches for the Linux kernel that address Intel VT-d IOMMU management.

Proactive Monitoring: Monitor system health and virtualization logs for anomalies related to IOMMU or hardware-assisted virtualization.

Compensating Controls: Ensure that virtualization hosts are running fully patched firmware and kernels to maintain hardware isolation.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Organizations utilizing Intel-based virtualization should treat this as a high-priority update. Updating the kernel and firmware is critical to maintaining the security boundary between virtualized instances.