CVE-2024-26709: powerpc/iommu: Fix the missing iommu_group_put() during platform domain attach
In the Linux kernel, the following vulnerability has been resolved:
powerpc/iommu: Fix the missing iommu_group_put() during platform domain attach
The function spapr_tce_platform_iommu_attach_dev() is missing to call
iommu_group_put() when the domain is already set. This refcount leak
shows up with BUG_ON() during DLPAR remove operation as:
KernelBug: Kernel bug in state 'None': kernel BUG at arch/powerpc/platforms/pseries/iommu.c:100!
Oops: Exception in kernel mode, sig: 5 [#1]
LE PAGE_SIZE=64K MMU=Radix SMP NR_CPUS=8192 NUMA pSeries
<snip>
Hardware name: IBM,9080-HEX POWER10 (raw) 0x800200 0xf000006 of:IBM,FW1060.00 (NH1060_016) hv:phyp pSeries
NIP: c0000000000ff4d4 LR: c0000000000ff4cc CTR: 0000000000000000
REGS: c0000013aed5f840 TRAP: 0700 Tainted: G I (6.8.0-rc3-autotest-g99bd3cb0d12e)
MSR: 8000000000029033 <SF,EE,ME,IR,DR,RI,LE> CR: 44002402 XER: 20040000
CFAR: c000000000a0d170 IRQMASK: 0
...
NIP iommu_reconfig_notifier+0x94/0x200
LR iommu_reconfig_notifier+0x8c/0x200
Call Trace:
iommu_reconfig_notifier+0x8c/0x200 (unreliable)
notifier_call_chain+0xb8/0x19c
blocking_notifier_call_chain+0x64/0x98
of_reconfig_notify+0x44/0xdc
of_detach_node+0x78/0xb0
ofdt_write.part.0+0x86c/0xbb8
proc_reg_write+0xf4/0x150
vfs_write+0xf8/0x488
ksys_write+0x84/0x140
system_call_exception+0x138/0x330
system_call_vectored_common+0x15c/0x2ec
The patch adds the missing iommu_group_put() call.
Security readout for executives and security teams
Plain-English summary
This Linux kernel issue is a reference-counting bug in PowerPC IOMMU handling. On affected systems, a dynamic hardware removal path can hit a kernel BUG and crash. The evidence points to IBM POWER pSeries-style environments, not general Linux desktops or cloud workloads. No active exploitation is reported in the supplied sources.
Executive priority
Treat this as targeted infrastructure risk, not broad enterprise exposure. Patch affected POWER/pSeries Linux systems during the next appropriate maintenance cycle, sooner where DLPAR operations are common or service availability is critical.
Technical view
spapr_tce_platform_iommu_attach_dev() failed to call iommu_group_put() when a domain was already set. The resulting refcount leak can surface during DLPAR remove, triggering BUG_ON() in arch/powerpc/platforms/pseries/iommu.c through iommu_reconfig_notifier. The patch adds the missing iommu_group_put() call.
Likely exposure
Exposure appears limited to Linux kernels in the affected range on PowerPC/pSeries systems using the relevant IOMMU and DLPAR paths. The source lists Linux 6.7 through 6.7.6 and 6.8 as affected, but distro backport status must be checked separately.
Exploitation context
The supplied sources do not show KEV listing, public exploitation, or weaponized exploit availability. The documented failure occurs during DLPAR remove and results in a kernel BUG, making availability the primary visible risk.
Researcher notes
Evidence is narrow: no CVSS, CWE, exploit status, or distro-specific advisory is provided. The primary artifact is a Linux stable fix for a missing put operation in PowerPC IOMMU code, with a crash trace showing the operational failure mode.
Mitigation direction
Apply a vendor kernel update containing the referenced upstream stable fix.
Prioritize IBM POWER or pSeries Linux hosts using DLPAR operations.
Check distribution advisories for backported fixes before relying on version numbers alone.
Plan maintenance windows for affected hosts where kernel updates require reboot.
Validation and detection
Inventory PowerPC/pSeries hosts and record running kernel versions.
Confirm whether installed kernel packages include the referenced stable commits.
Review logs for kernel BUG entries involving iommu_reconfig_notifier or pseries iommu.c.
Validate remediation in staging with normal administrative DLPAR workflows.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2024-26709 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.