CyberRota Analysis
AI-GeneratedA vulnerability in the Linux kernel affects the IOMMU SVA (Shared Virtual Addressing) mechanism, where a race condition allows a concurrent bind operation to access an uninitialized device pointer. This can lead to a potential dereference of a NULL pointer during the unbinding process, resulting in system instability or crashes. Organizations using Linux systems with IOMMU SVA enabled should prioritize addressing this issue to maintain system integrity and prevent potential disruptions.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: iommu/sva: Set handle->dev before the SVA handle is visible iommu_attach_device_pasid() installs the new SVA attach handle in the group PASID lookup before iommu_sva_bind_device() returns. A concurrent bind can therefore find and reuse the same handle after iommu_sva_lock is dropped. handle->dev was initialized after dropping iommu_sva_lock. This leaves a window where a racing bind can return a handle whose dev pointer is still NULL. A subsequent iommu_sva_unbind_device() can then dereference it via handle->dev->iommu_group. Initialize handle->dev before releasing iommu_sva_lock so any visible SVA handle is fully initialized.