]> git.ipfire.org Git - thirdparty/linux.git/commit
iommu/iommufd: Fix IOPF group ownership UAF
authorPeiyang He <peiyang_he@smail.nju.edu.cn>
Mon, 20 Jul 2026 08:50:16 +0000 (16:50 +0800)
committerJason Gunthorpe <jgg@nvidia.com>
Sun, 26 Jul 2026 16:16:21 +0000 (13:16 -0300)
commit738e6f32e61d80b554e37015ecb7bc620b88001c
treeb83cd4bd21a090aca842c9d017ff321208786d7e
parentc3b8ee84a965058b41275069d4696f37a8b14bf6
iommu/iommufd: Fix IOPF group ownership UAF

iopf_group_alloc() links each last-page IOPF group into the generic IOPF
pending list before invoking the domain fault handler.
iommufd_fault_iopf_handler() also queued an accepted group in the
IOMMUFD deliver list without removing it from the generic pending list.

When detach or HWPT replacement drops the device's IOPF reference count
to zero, an IOMMU driver may call iopf_queue_remove_device(). That
function responds to and frees groups through the generic pending list
without removing the same groups from IOMMUFD's deliver list or response
xarray. A later read, response, or cleanup can then access the freed
group and cause a UAF.

Fix this by dequeuing an accepted group from the generic pending list
before IOMMUFD queues it for userspace response.
Make iopf_group_response() send a response regardless of pending-list
membership, so the dequeued group can still be completed by IOMMUFD.

Link: https://patch.msgid.link/r/3CFD314D0FE4D7EC+20260720085017.3998878-2-peiyang_he@smail.nju.edu.cn
Closes: https://lore.kernel.org/all/B4F28798E2E784CA+d29f723c-b2b5-4b67-8d1c-4f7b9b0b27cb@smail.nju.edu.cn/
Fixes: 34765cbc679c ("iommufd: Associate fault object with iommufd_hw_pgtable")
Cc: stable@vger.kernel.org
Tested-by: Peiyang He <peiyang_he@smail.nju.edu.cn>
Assisted-by: Codex:gpt-5.6-sol
Signed-off-by: Peiyang He <peiyang_he@smail.nju.edu.cn>
Reviewed-by: Kevin Tian <kevin.tian@intel.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
drivers/iommu/io-pgfault.c
drivers/iommu/iommufd/eventq.c
include/linux/iommu.h