← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 15, 2026 · 13:18via CVEFeed

CVE-2026-74573 - iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE

Brief

CVE ID : CVE-2026-74573

Published : Aug. 15, 2026, 1:18 p. m.

  • 7 hours, 48 minutes ago

Description : In the Linux kernel, the following vulnerability has been resolved:

iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE

arm_vsmmu_vsid_to_sid() maps a guest's vSID to a single physical Stream ID taken from master-streams[0], assuming a device has exactly one stream. A device with several streams gets only its first one mapped, so a guest vSID invalidation cannot reach the others' ATC and IOTLB entries; a device with none makes master-streams a ZERO_SIZE_PTR, read out of bounds.

Add an arm_vsmmu_vdevice_init() op to reject the vDEVICE with -EOPNOTSUPP when master-num_streams is not one, rather than mapping it silently.

Severity: 0.0

Read more on CVEFeed