---
cve: "CVE-2026-89453"
severity: "LOW"
cvss: 3.1
epss: "20%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-09-11 20:19:25"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-18T18:16:01+02:00"
---

# CVE-2026-89453

> 3.1 LOW

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

iommu/amd: Put PCI device after handling PPR faults

iommu_call_iopf_notifier() looks up the requester with
pci_get_domain_bus_and_slot(), which returns a PCI device with its
reference count incremented.

Neither the successful iommu_report_device_fault() path nor the abort
path drops that reference, so every handled PPR request leaks a PCI
device reference.

This is the same ownership rule that was fixed for the old iommu_v2
ppr_notifier() path by commit 6cf0981c2233 ("iommu/amd: Fix pci device
refcount leak in ppr_notifier()"), but iommu_call_iopf_notifier() was
added later as a separate PPR/IOPF notifier path.

Drop the PCI device reference after handling the PPR entry.

## Patch verfügbar (OSV)

- Kernel ≥ 6.12.109
- Kernel ≥ 6.18.50
- Kernel ≥ 7.2.4

## Referenzen

- <https://git.kernel.org/stable/c/1de4443f85e4405af00153cdf8ba73ff12a65036>
- <https://git.kernel.org/stable/c/cfc5c1b2caa176dfd40b873a6ff07b11da34cc3e>
- <https://git.kernel.org/stable/c/d1470e16c1977e6c94fadf6048deafaa4d150fec>
- <https://git.kernel.org/stable/c/af3b69b16383fbc8fe5f61b5b0150d2e41ede71f>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-89453) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
