{"id":"CVE-2026-89453","title":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/amd: Put PCI device after handling PPR faults\n\niommu_call_iopf_notifier() looks up the requester with\npci_get_domain_bus_and_slot(), which returns a PCI device wi…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/amd: Put PCI device after handling PPR faults\n\niommu_call_iopf_notifier() looks up the requester with\npci_get_domain_bus_and_slot(), which returns a PCI device wi…","severity":"medium","vendor":"Linux","product":"Linux","affected":["Linux >= 978d626b8f1a239acc635323d731c77eae54eb61 < 1de4443f85e4405af00153cdf8ba73ff12a65036","Linux >= 978d626b8f1a239acc635323d731c77eae54eb61 < cfc5c1b2caa176dfd40b873a6ff07b11da34cc3e","Linux >= 978d626b8f1a239acc635323d731c77eae54eb61 < d1470e16c1977e6c94fadf6048deafaa4d150fec","Linux >= 978d626b8f1a239acc635323d731c77eae54eb61 < af3b69b16383fbc8fe5f61b5b0150d2e41ede71f","Linux 6.10"],"published":"2026-09-11","updated":"2026-09-11","sourceUpdated":"2026-09-11T20:19:25.967","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-89453","references":[{"url":"https://git.kernel.org/stable/c/1de4443f85e4405af00153cdf8ba73ff12a65036","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af3b69b16383fbc8fe5f61b5b0150d2e41ede71f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cfc5c1b2caa176dfd40b873a6ff07b11da34cc3e","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d1470e16c1977e6c94fadf6048deafaa4d150fec","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89453.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89453"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532501"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89453"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89453"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89453.mbox"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ingestedAt":"2026-09-14T07:03:59.522Z","epss":0.002,"epssPercentile":0.10111,"cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":["CWE-911"],"slug":"CVE-2026-89453","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\niommu/amd: Put PCI device after handling PPR faults\n\niommu_call_iopf_notifier() looks up the requester with\npci_get_domain_bus_and_slot(), which returns a PCI device with its\nreference count incremented.\n\nNeither the successful iommu_report_device_fault() path nor the abort\npath drops that reference, so every handled PPR request leaks a PCI\ndevice reference.\n\nThis is the same ownership rule that was fixed for the old iommu_v2\nppr_notifier() path by commit 6cf0981c2233 (\"iommu/amd: Fix pci device\nrefcount leak in ppr_notifier()\"), but iommu_call_iopf_notifier() was\nadded later as a separate PPR/IOPF notifier path.\n\nDrop the PCI device reference after handling the PPR entry.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Low · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89453.json)","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":203949,"id":"CVE-2026-89453","ts":1789490230753,"field":"cvss","old":null,"new":"5.5"},{"seq":203948,"id":"CVE-2026-89453","ts":1789490230753,"field":"severity","old":"none","new":"medium"},{"seq":147111,"id":"CVE-2026-89453","ts":1789270195216,"field":"cvss","old":null,"new":"4.4"},{"seq":147110,"id":"CVE-2026-89453","ts":1789270195216,"field":"severity","old":"none","new":"medium"},{"seq":108858,"id":"CVE-2026-89453","ts":1789183729283,"field":"cvss","old":null,"new":"4.4"},{"seq":108857,"id":"CVE-2026-89453","ts":1789183729283,"field":"severity","old":"none","new":"medium"}]}