Fault-response mishandling via mismatched hardware page table
Published Sep 4, 2026 · Updated Sep 4, 2026
Logic error in affected Linux kernel iommufd releases allows attackers an unspecified impact during device-domain replacement. iommufd_hwpt_replace_device passes the new hardware page table with the old domain handle, so iommufd_auto_response_faults scans the wrong fault queues. Published Linux material does not identify the required attacker access or the resulting security consequence.
Summary
What happened
Logic error in affected Linux kernel iommufd releases allows attackers an unspecified impact during device-domain replacement. iommufd_hwpt_replace_device passes the new hardware page table with the old domain handle, so iommufd_auto_response_faults scans the wrong fault queues. Published Linux material does not identify the required attacker access or the resulting security consequence.
The record
- CVE
- CVE-2026-80894
- Published
- Sep 4, 2026
- Updated
- Sep 4, 2026
- Vendor
- The Linux Kernel Organization
- Product
- Linux
- Classifications
- Unavailable
- Attack vector
- Unavailable
- Privileges
- Unavailable
Timeline
How it unfolded
- Sep 4, 2026CVE publishedPublication date reported by the CVE source.
- Sep 4, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=1e0216b6a58c79b5ee91c78706d5f560e4d1f56f
- Affected versionversion=4b23c4b991eb90cc7bca42e9f81142feedd4bb56
- Affected versionversion=6.12.24 <6.12.105
- Affected versionversion=6.13.12 <6.14
- Affected versionversion=6.14.3 <6.15
- Affected versionversion=6.15
- Affected versionversion=6d11543bf37abdf60b8e6022a62fccfb82a5fe2e <adb87155b67f9759ff010c0a99559f5bffa45dcf
- Affected versionversion=fb21b1568adaa76af7a8c853f37c60fba8b28661 <564ac339c0f8bada4e77a57a92bab9d3df635e07
- Affected versionversion=fb21b1568adaa76af7a8c853f37c60fba8b28661 <8eb077025279304268bd58657f0af3d388822b21
- Affected versionversion=fb21b1568adaa76af7a8c853f37c60fba8b28661 <ba5c0f28a26e7d9be1e0997f8920dd638e2782fd
What conditions does exploitation require?
What is affected?
Published CVSS scores
No CVSS assessment is available in this record.
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
No sourced classifications are available.
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo