CVE-2026-98004: iommu/riscv: Serialize command queue publishing

Published Sep 25, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

iommu/riscv: Serialize command queue publishing

Serialize command queue publishing so software producer state advances only after a command is written and the hardware tail is updated. Wait for hardware consumption outside the queue lock when the command queue is full so other CPUs are not blocked behind a long poll.

Affected Software

1 affected component
Linux Linux kernel

Event History

Sep 25, 2026
CVE Published
via MITRE·10:23 AM
Data Sourced
via MITRE·10:23 AM
Description
Data Sourced
via NVD·11:17 AM
Description

Frequently Asked Questions

1

Which fixes are referenced for this issue?

The provided references identify fixes in the stable kernel history with commit IDs 6d4c12ab9ab8db87411c863a54e0e97f9197afde and ca58afa40946acd252a50fa4d4a86f15847a3d7d. No affected or fixed kernel version ranges are provided.

2

How does the fix avoid blocking other CPUs when the command queue is full?

It waits for hardware consumption outside the command-queue lock. This prevents other CPUs from being held behind a potentially long polling operation while the queue is full.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203