---
id: CVE-2025-21876
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  iommu/vt-d: Fix suspicious RCU usage

  Commit <d74169ceb0d2> ("iommu/vt-d: Allocate DMAR fault interrupts
  locally") moved the call to enable_drhd_fault_handling() to a c…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  iommu/vt-d: Fix suspicious RCU usage

  Commit <d74169ceb0d2> ("iommu/vt-d: Allocate DMAR fault interrupts
  locally") moved the call to enable_drhd_fault_handling() to a c…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 6.10, < 6.12.18'
  - 'linux_kernel >= 6.13, < 6.13.6'
  - linux_kernel = 6.14
patched:
  - linux_kernel 6.13.6
published: '2025-03-27'
updated: '2026-07-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-21876'
references:
  - url: 'https://git.kernel.org/stable/c/4117c72938493a77ab53cc4b8284be8fb6ec8065'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b150654f74bf0df8e6a7936d5ec51400d9ec06d8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c603ccbe91d189849e1439134598ec567088dcec'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-21876.json
  - url: 'https://access.redhat.com/security/cve/CVE-2025-21876'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2355411'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-21876'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-21876'
  - url: >-
      https://lore.kernel.org/linux-cve-announce/2025032710-CVE-2025-21876-6c2f@gregkh/T
tags:
  - nvd
  - csaf
  - vex
  - red-hat
  - score-dispute
epss: 0.00212
epssPercentile: 0.10176
ingestedAt: '2026-07-30T06:53:10.648Z'
cwe:
  - CWE-413
scores:
  nvd: 8.8
  vendor: 3.3
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

iommu/vt-d: Fix suspicious RCU usage

Commit <d74169ceb0d2> ("iommu/vt-d: Allocate DMAR fault interrupts
locally") moved the call to enable_drhd_fault_handling() to a code
path that does not hold any lock while traversing the drhd list. Fix
it by ensuring the dmar_global_lock lock is held when traversing the
drhd list.

Without this fix, the following warning is triggered:
 =============================
 WARNING: suspicious RCU usage
 6.14.0-rc3 #55 Not tainted
 -----------------------------
 drivers/iommu/intel/dmar.c:2046 RCU-list traversed in non-reader section!!
               other info that might help us debug this:
               rcu_scheduler_active = 1, debug_locks = 1
 2 locks held by cpuhp/1/23:
 #0: ffffffff84a67c50 (cpu_hotplug_lock){++++}-{0:0}, at: cpuhp_thread_fun+0x87/0x2c0
 #1: ffffffff84a6a380 (cpuhp_state-up){+.+.}-{0:0}, at: cpuhp_thread_fun+0x87/0x2c0
 stack backtrace:
 CPU: 1 UID: 0 PID: 23 Comm: cpuhp/1 Not tainted 6.14.0-rc3 #55
 Call Trace:
  <TASK>
  dump_stack_lvl+0xb7/0xd0
  lockdep_rcu_suspicious+0x159/0x1f0
  ? __pfx_enable_drhd_fault_handling+0x10/0x10
  enable_drhd_fault_handling+0x151/0x180
  cpuhp_invoke_callback+0x1df/0x990
  cpuhp_thread_fun+0x1ea/0x2c0
  smpboot_thread_fn+0x1f5/0x2e0
  ? __pfx_smpboot_thread_fn+0x10/0x10
  kthread+0x12a/0x2d0
  ? __pfx_kthread+0x10/0x10
  ret_from_fork+0x4a/0x60
  ? __pfx_kthread+0x10/0x10
  ret_from_fork_asm+0x1a/0x30
  </TASK>

Holding the lock in enable_drhd_fault_handling() triggers a lockdep splat
about a possible deadlock between dmar_global_lock and cpu_hotplug_lock.
This is avoided by not holding dmar_global_lock when calling
iommu_device_register(), which initiates the device probe process.

## Affected

- `linux_kernel >= 6.10, < 6.12.18`
- `linux_kernel >= 6.13, < 6.13.6`
- `linux_kernel = 6.14`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.13.6`

## Vendor advisories

- **Red Hat VEX** · Low · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9 · updated 2026-09-13 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-21876.json)
