iommu/amd: move wait_on_sem() out of spinlock
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 0.3%
exploitation probability
0.3%top 73% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
iommu/amd: move wait_on_sem() out of spinlock
With iommu.strict=1, the existing completion wait path can cause soft
lockups under stressed environment, as wait_on_sem() busy-waits under the
spinlock with interrupts disabled.
Move the completion wait in iommu_completion_wait() out of the spinlock.
wait_on_sem() only polls the hardware-updated cmd_sem and does not require
iommu->lock, so holding the lock during the busy wait unnecessarily
increases contention and extends the time with interrupts disabled.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/496269d12072ecb219826485bdbec70c92a8eef5https://git.kernel.org/stable/c/715c263119fd1b918a9fcbd8a36ea5b604a46324https://git.kernel.org/stable/c/d2a0cac10597068567d336e85fa3cbdbe8ca62bfhttps://git.kernel.org/stable/c/e15768e68820142077bbca402d8e902f64ade1b0https://git.kernel.org/stable/c/f2f65b28d802a667119147444ec2ae33eebf9a58