{"id":"CVE-2026-45945","title":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Fix race condition during PASID entry replacement\n\nThe Intel VT-d PASID table entry is 512 bits (64 bytes)","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Fix race condition during PASID entry replacement\n\nThe Intel VT-d PASID table entry is 512 bits (64 bytes). When replacing\nan active PASID entry (e.g., duri…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-362"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 6.13, < 6.19.4"],"patched":["linux_kernel 6.19.4"],"published":"2026-05-27","updated":"2026-07-18","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-45945","references":[{"url":"https://git.kernel.org/stable/c/4718007870547e1efebbdd6745d9fce58f008fef","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/66a7aff480a82b8642b3991fed5fdc9780022157","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c3b1edea3791fa91ab7032faa90355913ad9451b","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd"],"epss":0.00134,"epssPercentile":0.03275,"ingestedAt":"2026-07-18T16:23:45.854Z","slug":"CVE-2026-45945","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Fix race condition during PASID entry replacement\n\nThe Intel VT-d PASID table entry is 512 bits (64 bytes). When replacing\nan active PASID entry (e.g., during domain replacement), the current\nimplementation calculates a new entry on the stack and copies it to the\ntable using a single structure assignment.\n\n        struct pasid_entry *pte, new_pte;\n\n        pte = intel_pasid_get_entry(dev, pasid);\n        pasid_pte_config_first_level(iommu, &new_pte, ...);\n        *pte = new_pte;\n\nBecause the hardware may fetch the 512-bit PASID entry in multiple\n128-bit chunks, updating the entire entry while it is active (Present\nbit set) risks a \"torn\" read. In this scenario, the IOMMU hardware\ncould observe an inconsistent state — partially new data and partially\nold data — leading to unpredictable behavior or spurious faults.\n\nFix this by removing the unsafe \"replace\" helpers and following the\n\"clear-then-update\" flow, which ensures the Present bit is cleared and\nthe required invalidation handshake is completed before the new\nconfiguration is applied.\n\n## Affected\n\n- `linux_kernel >= 6.13, < 6.19.4`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 6.19.4`","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}