RE: [PATCH v3 1/2] iommu/iommufd: Fix IOPF group ownership UAF

From: Tian, Kevin

Date: Mon Jul 20 2026 - 05:48:33 EST


> From: Peiyang He <peiyang_he@xxxxxxxxxxxxxxxx>
> Sent: Monday, July 20, 2026 4:50 PM
>
> iopf_group_alloc() links each last-page IOPF group into the generic IOPF
> pending list before invoking the domain fault handler.
> iommufd_fault_iopf_handler() also queued an accepted group in the
> IOMMUFD deliver list without removing it from the generic pending list.
>
> When detach or HWPT replacement drops the device's IOPF reference count
> to zero, an IOMMU driver may call iopf_queue_remove_device(). That
> function responds to and frees groups through the generic pending list
> without removing the same groups from IOMMUFD's deliver list or response
> xarray. A later read, response, or cleanup can then access the freed
> group and cause a UAF.
>
> Fix this by dequeuing an accepted group from the generic pending list
> before IOMMUFD queues it for userspace response.
> Make iopf_group_response() send a response regardless of pending-list
> membership, so the dequeued group can still be completed by IOMMUFD.
>
> Closes: https://lore.kernel.org/all/B4F28798E2E784CA+d29f723c-b2b5-4b67-
> 8d1c-4f7b9b0b27cb@xxxxxxxxxxxxxxxx/
> Fixes: 34765cbc679c ("iommufd: Associate fault object with
> iommufd_hw_pgtable")
> Cc: stable@xxxxxxxxxxxxxxx
> Tested-by: Peiyang He <peiyang_he@xxxxxxxxxxxxxxxx>
> Assisted-by: Codex:gpt-5.6-sol
> Signed-off-by: Peiyang He <peiyang_he@xxxxxxxxxxxxxxxx>

Reviewed-by: Kevin Tian <kevin.tian@xxxxxxxxx>