# CVE-2026-89453

## Summary

- **CVE ID:** CVE-2026-89453
- **Severity:** UNKNOWN
- **CVSS Score:** 1.51
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 16, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

iommu/amd: Put PCI device after handling PPR faults

iommu_call_iopf_notifier() looks up the requester with
pci_get_domain_bus_and_slot(), which returns a PCI device with its
reference count incremented.

Neither the successful iommu_report_device_fault() path nor the abort
path drops that reference, so every handled PPR request leaks a PCI
device reference.

This is the same ownership rule that was fixed for the old iommu_v2
ppr_notifier() path by commit 6cf0981c2233 ("iommu/amd: Fix pci device
refcount leak in ppr_notifier()"), but iommu_call_iopf_notifier() was
added later as a separate PPR/IOPF notifier path.

Drop the PCI device reference after handling the PPR entry.

## Affected Products

- Linux — Linux (978d626b8f1a239acc635323d731c77eae54eb61)
- Linux — Linux (6.10)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)

## References

- [CNA](https://git.kernel.org/stable/c/1de4443f85e4405af00153cdf8ba73ff12a65036)
- [CNA](https://git.kernel.org/stable/c/cfc5c1b2caa176dfd40b873a6ff07b11da34cc3e)
- [CNA](https://git.kernel.org/stable/c/d1470e16c1977e6c94fadf6048deafaa4d150fec)
- [CNA](https://git.kernel.org/stable/c/af3b69b16383fbc8fe5f61b5b0150d2e41ede71f)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.20%
- **EPSS Percentile:** 10.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._