CVE-2026-89448
Linux · Kernel
A misconfiguration in the Linux kernel IOMMU subsystem allows for improper ACS enforcement when tboot is enabled, potentially leading to security bypasses.
Executive summary
A critical security flaw in the Linux kernel IOMMU subsystem can be exploited to bypass hardware-level protections, potentially resulting in full system compromise.
Vulnerability
The vulnerability exists within the intel_iommu driver, where the logic fails to account for tboot (Trusted Boot) states when determining ACS (Access Control Services) requirements. This allows an attacker with local access to trigger a misconfiguration that weakens IOMMU protections, even when system security policies should mandate them.
Business impact
The CVSS score of 9.3 reflects the high severity of this flaw, as it permits an attacker to achieve scope-changing impact on the confidentiality, integrity, and availability of the host system. Successful exploitation could lead to unauthorized access to kernel memory, privilege escalation, or total system compromise, posing a significant risk to data privacy and operational continuity.
Remediation
Immediate Action: Apply the vendor-provided kernel updates to versions 6.12.109, 6.18.50, 7.2.4, or later immediately.
Proactive Monitoring: Monitor system logs for unexpected kernel module behavior or unauthorized attempts to manipulate IOMMU settings.
Compensating Controls: Ensure that Trusted Boot (tboot) configurations are audited and that unnecessary hardware access is restricted through existing kernel-level hardening parameters.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical nature of this kernel-level vulnerability, security teams should prioritize patching affected Linux distributions as soon as stable updates are available. Organizations operating systems that rely on Intel IOMMU and tboot for isolation should treat this as a high-priority remediation item to prevent potential bypass of hardware security boundaries.
More Linux CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.3 (3.1)
- Analyst report written