LiveActive security incident?Get immediate response
CVE Record

CVE-2024-26709: powerpc/iommu: Fix the missing iommu_group_put() during platform domain attach

In the Linux kernel, the following vulnerability has been resolved: powerpc/iommu: Fix the missing iommu_group_put() during platform domain attach The function spapr_tce_platform_iommu_attach_dev() is missing to call iommu_group_put() when the domain is already set. This refcount leak shows up with BUG_ON() during DLPAR remove operation as: KernelBug: Kernel bug in state 'None': kernel BUG at arch/powerpc/platforms/pseries/iommu.c:100! Oops: Exception in kernel mode, sig: 5 [#1] LE PAGE_SIZE=64K MMU=Radix SMP NR_CPUS=8192 NUMA pSeries <snip> Hardware name: IBM,9080-HEX POWER10 (raw) 0x800200 0xf000006 of:IBM,FW1060.00 (NH1060_016) hv:phyp pSeries NIP: c0000000000ff4d4 LR: c0000000000ff4cc CTR: 0000000000000000 REGS: c0000013aed5f840 TRAP: 0700 Tainted: G I (6.8.0-rc3-autotest-g99bd3cb0d12e) MSR: 8000000000029033 <SF,EE,ME,IR,DR,RI,LE> CR: 44002402 XER: 20040000 CFAR: c000000000a0d170 IRQMASK: 0 ... NIP iommu_reconfig_notifier+0x94/0x200 LR iommu_reconfig_notifier+0x8c/0x200 Call Trace: iommu_reconfig_notifier+0x8c/0x200 (unreliable) notifier_call_chain+0xb8/0x19c blocking_notifier_call_chain+0x64/0x98 of_reconfig_notify+0x44/0xdc of_detach_node+0x78/0xb0 ofdt_write.part.0+0x86c/0xbb8 proc_reg_write+0xf4/0x150 vfs_write+0xf8/0x488 ksys_write+0x84/0x140 system_call_exception+0x138/0x330 system_call_vectored_common+0x15c/0x2ec The patch adds the missing iommu_group_put() call.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

This Linux kernel issue is a reference-counting bug in PowerPC IOMMU handling. On affected systems, a dynamic hardware removal path can hit a kernel BUG and crash. The evidence points to IBM POWER pSeries-style environments, not general Linux desktops or cloud workloads. No active exploitation is reported in the supplied sources.

Executive priority

Treat this as targeted infrastructure risk, not broad enterprise exposure. Patch affected POWER/pSeries Linux systems during the next appropriate maintenance cycle, sooner where DLPAR operations are common or service availability is critical.

Technical view

spapr_tce_platform_iommu_attach_dev() failed to call iommu_group_put() when a domain was already set. The resulting refcount leak can surface during DLPAR remove, triggering BUG_ON() in arch/powerpc/platforms/pseries/iommu.c through iommu_reconfig_notifier. The patch adds the missing iommu_group_put() call.

Likely exposure

Exposure appears limited to Linux kernels in the affected range on PowerPC/pSeries systems using the relevant IOMMU and DLPAR paths. The source lists Linux 6.7 through 6.7.6 and 6.8 as affected, but distro backport status must be checked separately.

Exploitation context

The supplied sources do not show KEV listing, public exploitation, or weaponized exploit availability. The documented failure occurs during DLPAR remove and results in a kernel BUG, making availability the primary visible risk.

Researcher notes

Evidence is narrow: no CVSS, CWE, exploit status, or distro-specific advisory is provided. The primary artifact is a Linux stable fix for a missing put operation in PowerPC IOMMU code, with a crash trace showing the operational failure mode.

Mitigation direction

  • Apply a vendor kernel update containing the referenced upstream stable fix.
  • Prioritize IBM POWER or pSeries Linux hosts using DLPAR operations.
  • Check distribution advisories for backported fixes before relying on version numbers alone.
  • Plan maintenance windows for affected hosts where kernel updates require reboot.

Validation and detection

  • Inventory PowerPC/pSeries hosts and record running kernel versions.
  • Confirm whether installed kernel packages include the referenced stable commits.
  • Review logs for kernel BUG entries involving iommu_reconfig_notifier or pseries iommu.c.
  • Validate remediation in staging with normal administrative DLPAR workflows.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2024-26709 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
2ADP providers
3Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
CVECVE Program Container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinuxa8ca9fc9134c1a43e6d4db7ff59496bbd7075def, a8ca9fc9134c1a43e6d4db7ff59496bbd7075defunaffected
LinuxLinux6.7, 0, 6.7.6, 6.8affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.