CVE-2026-45862: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Flush cache for PASID table before using it When writing the address of a freshly allocated zero-initialized PASID table to a PASID directory entry, do that after the CPU cache flush for this PASID table, not before it, to avoid the time window when this PASID table may be already used by non-coherent IOMMU hardware while its contents in RAM is still some random old data, not zero-initialized.

Affected products

  • Linux Linux Kernel: from 5.4.237, before 5.5 (fixed in 5.5); from 5.10.175, before 5.10.252 (fixed in 5.10.252); from 5.15.103, before 5.15.202 (fixed in 5.15.202); from 6.1.16, before 6.1.165 (fixed in 6.1.165); from 6.2.3, before 6.6.128 (fixed in 6.6.128); from 6.7, before 6.12.75 (fixed in 6.12.75); …

Published 2026-05-27. Last modified 2026-06-25.