CVE-2026-43220
In the Linux kernel, the following vulnerability has been resolved: iommu/amd: serialize sequence allocation under concurrent TLB invalidations With concurrent TLB invalidations, completion wait randomly gets timed out because cmd_sem_val was incremented outside the IOMMU spinlock, allowing CMD_COMPL_WAIT commands to be queued out of sequence and breaking the ordering assumption in wait_on_sem(). Move the cmd_sem_val increment under iommu->lock so completion sequence allocation is serialized with command queuing. And remove the unnecessary return.
- Affected products
- Linux Kernel
- Linux Linux Kernel
- < 6.7, 6.13
- CVSS 3.1
- 5.5 MEDIUM
- EPSS
- 0.1% (3th percentile)
- NVD status
- Modified
- Published
- 2026-05-06
CVE-2026-43220 at NVD
2 known exploits for CVE-2026-43220
Proof-of-concept code and exploit modules indexed by Sploitus