A flaw was found in the way iommu mapping failures were handled in kvmiommumappages() function in the Linux kernel. A privileged user in the guest could use this flaw to crash the host in case the guest has access to passed in device.
Acknowledgements:
Red Hat would like to thank Jack Morgenstein of Mellanox for reporting this issue; the security impact of this issue was discovered by Michael Tsirkin of Red Hat.