---
id: CVE-2026-45945
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  iommu/vt-d: Fix race condition during PASID entry replacement

  The Intel VT-d PASID table entry is 512 bits (64 bytes)
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  iommu/vt-d: Fix race condition during PASID entry replacement

  The Intel VT-d PASID table entry is 512 bits (64 bytes). When replacing
  an active PASID entry (e.g., duri…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-362
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 6.13, < 6.19.4'
patched:
  - linux_kernel 6.19.4
published: '2026-05-27'
updated: '2026-07-18'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-45945'
references:
  - url: 'https://git.kernel.org/stable/c/4718007870547e1efebbdd6745d9fce58f008fef'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/66a7aff480a82b8642b3991fed5fdc9780022157'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c3b1edea3791fa91ab7032faa90355913ad9451b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00134
epssPercentile: 0.03275
ingestedAt: '2026-07-18T16:23:45.854Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

iommu/vt-d: Fix race condition during PASID entry replacement

The Intel VT-d PASID table entry is 512 bits (64 bytes). When replacing
an active PASID entry (e.g., during domain replacement), the current
implementation calculates a new entry on the stack and copies it to the
table using a single structure assignment.

        struct pasid_entry *pte, new_pte;

        pte = intel_pasid_get_entry(dev, pasid);
        pasid_pte_config_first_level(iommu, &new_pte, ...);
        *pte = new_pte;

Because the hardware may fetch the 512-bit PASID entry in multiple
128-bit chunks, updating the entire entry while it is active (Present
bit set) risks a "torn" read. In this scenario, the IOMMU hardware
could observe an inconsistent state — partially new data and partially
old data — leading to unpredictable behavior or spurious faults.

Fix this by removing the unsafe "replace" helpers and following the
"clear-then-update" flow, which ensures the Present bit is cleared and
the required invalidation handshake is completed before the new
configuration is applied.

## Affected

- `linux_kernel >= 6.13, < 6.19.4`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.19.4`
