# CVE-2026-89451

## Summary

- **CVE ID:** CVE-2026-89451
- **Severity:** UNKNOWN
- **CVSS Score:** 1.51
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 16, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

iommu/sva: Set handle->dev before the SVA handle is visible

iommu_attach_device_pasid() installs the new SVA attach handle in the
group PASID lookup before iommu_sva_bind_device() returns. A concurrent
bind can therefore find and reuse the same handle after iommu_sva_lock is
dropped.

handle->dev was initialized after dropping iommu_sva_lock. This leaves a
window where a racing bind can return a handle whose dev pointer is still
NULL. A subsequent iommu_sva_unbind_device() can then dereference it via
handle->dev->iommu_group.

Initialize handle->dev before releasing iommu_sva_lock so any visible SVA
handle is fully initialized.

## Affected Products

- Linux — Linux (be51b1d6bbff48c7d1943a8ff1e5a55777807f6e)
- Linux — Linux (6.2)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)

## References

- [CNA](https://git.kernel.org/stable/c/bcffb1c75da8fc9d51168ff9f09d471c26507912)
- [CNA](https://git.kernel.org/stable/c/968e9a1f71140c86dc4092f6b361e997923f3813)
- [CNA](https://git.kernel.org/stable/c/37a96a30617a4c96f048a5874c00509bc4fe4d85)
- [CNA](https://git.kernel.org/stable/c/530f8f9c3546cb3ebee1b135375aaee08a073ebb)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.20%
- **EPSS Percentile:** 10.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._