Kernel IOMMU (VT-d) bug enables DMA-based host/VM compromise; Linux is ubiquitous in servers/cloud—warrants broad, immediate attention.
CVE-2026-74439
VT-d PASID teardown bug lets IOMMU walk freed entries, enabling DMA-based host/VM compromise.
Is CVE-2026-74439 being exploited?
Not confirmed. CVE-2026-74439 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.13% probability of exploitation in the next 30 days.
How severe is CVE-2026-74439?
CVE-2026-74439 is rated Critical with a CVSS score of 9.3. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-74439?
Yes. A fix has been recorded for CVE-2026-74439. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-74439 affect?
CVE-2026-74439 affects Linux kernel (iommu/vt-d), Intel VT-d IOMMU-enabled systems, Virtualization hosts with PASID-capable devices, PCIe devices supporting PASID. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-74439?
Apply patched kernel/backport immediately; isolate/unplug untrusted PCIe devices or disable PASID/IOMMU until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
A malicious PCIe device or guest can cause IOMMU to use freed PASID entries, enabling arbitrary DMA reads/writes, data disclosure, corruption, or host/VM compromise.
Immediate action required
- affected>= 81e921fd321614c2ad8ac333b041aae1da7a1c6d and < e9e83bcfe37dc719182500dd823c03ab57d934f0
- affected>= 81e921fd321614c2ad8ac333b041aae1da7a1c6d and < 588718101e8449605f1c7e858fecb7cfa701cdab
- affected>= 81e921fd321614c2ad8ac333b041aae1da7a1c6d and < 7fd4077dc92b91b1b844333c0a06bb9e286db10a
- affected>= 81e921fd321614c2ad8ac333b041aae1da7a1c6d and < f46452c3df7a8d8a5addc0926e76ef19ea7da0a0
- affected333fe86968482ca701c609af590003bcea450e8f
- affected>= 6.8.2 and < 6.9
- affected6.9
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.