PatchSiren cyber security CVE debrief
CVE-2026-43220 Linux CVE debrief
CVE-2026-43220 is a Linux kernel AMD IOMMU availability issue where concurrent TLB invalidations could cause completion waits to time out. The problem was that cmd_sem_val was incremented outside the IOMMU spinlock, which let CMD_COMPL_WAIT commands be queued out of sequence and violate the ordering assumption in wait_on_sem(). The published fix serializes completion-sequence allocation under iommu->lock and removes an unnecessary return.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-06
- Original CVE updated
- 2026-05-17
- Advisory published
- 2026-05-06
- Advisory updated
- 2026-05-17
Who should care
Linux kernel maintainers, distro security teams, and operators running affected 6.6.x or 6.12.x kernel branches—especially systems using AMD IOMMU paths where local users or workloads could trigger the timing issue.
Technical summary
According to the CVE description, concurrent TLB invalidations exposed a race in the AMD IOMMU command path. cmd_sem_val was incremented outside the IOMMU spinlock, so CMD_COMPL_WAIT commands could be allocated out of order relative to queued invalidation commands. That broke the sequencing assumption used by wait_on_sem(), leading to random completion-wait timeouts. NVD lists the issue as affecting Linux kernel versions starting with 6.6.128 before 6.7, and 6.12.75 before 6.13.
Defensive priority
Moderate: prioritize patching affected kernel builds because the flaw can disrupt availability, but the published CVSS vector indicates local access and low privileges are required.
Recommended defensive actions
- Upgrade Linux kernel builds on affected branches to versions containing the upstream/stable fix.
- Prioritize hosts running AMD IOMMU-capable systems on the affected 6.6.x and 6.12.x lines.
- Verify vendor backports for your distribution rather than relying only on base version numbers.
- If immediate patching is delayed, reduce exposure by restricting local user access on systems where feasible and monitor for kernel log evidence of repeated completion-wait timeouts.
- Track the linked kernel patches and your distro advisories for backport status.
Evidence notes
The CVE description states the root cause: cmd_sem_val was incremented outside the IOMMU spinlock, allowing out-of-sequence CMD_COMPL_WAIT commands and timeout behavior in wait_on_sem(). NVD marks the vulnerability as modified and lists affected Linux kernel ranges as 6.6.128 through before 6.7, and 6.12.75 through before 6.13. The linked git.kernel.org references are official kernel patch and source references associated with the fix.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-43220 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-43220
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-43220 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43220
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/48caa7542a795c9679ec1bd1bc2592e05a7369a4
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/5000ce7fcb31067566a1a1a2e5b5bbff93625242
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/9e249c48412828e807afddc21527eb734dc9bd3d
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d51bf43193b1e95dc4e34e540dc76e19def2ae5a
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/fca7aa0264ae99e5ff287d0ced5af0b82b121c4f
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.