Description
In the Linux kernel, the following vulnerability has been resolved:

iommu/tegra241-cmdqv: Fix VINTF0 leak on the init-failure path

tegra241_cmdqv_init_structures() allocates VINTF0 with kzalloc_obj(), inits
it, and preallocates its logical VCMDQs. Two of its error paths leak.

When tegra241_cmdqv_init_vintf() fails it returns before VINTF0 reaches the
cmdqv->vintfs[] array, so the devres unwind on probe failure cannot reach
it; free it directly there.

A later VCMDQ preallocation failure instead leaves VINTF0 published, and so
this time the unwind does reach tegra241_cmdqv_remove_vintf(), which then
frees it from vintf->hyp_own. But tegra241_vintf_hw_init() sets that flag
only afterward, from a HW read-back, so the still-uninited VINTF0 reads as
guest-owned and leaks, with mutex_destroy() and ida_destroy() run on fields
it never set up.

Decide ownership from vintf->idx instead, the index assigned when its id is
allocated: idx 0 is the kernel-owned VINTF0, while idx >= 1 marks a guest
VINTF. So the in-kernel free decision in tegra241_cmdqv_remove_vintf() and
tegra241_vintf_free_lvcmdq() now keys on idx too, and hyp_own stays a pure
HW-readback state.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Resource Leak
Action: Patch
AI Analysis

Impact

The kernel vulnerability involves a leak of the kernel‑owned VINTF0 resource in the Tegra 241 IOMMU driver when certain initialization failures occur. When tegra241_cmdqv_init_vintf fails, the allocated VINTF0 is not added to the driver’s resource array, preventing the normal unroll of the device’s resources during probe failure and causing the memory, mutex, and IDA structures to remain allocated. Later, a failure in a preallocation step leaves the public reference to that uninitialized VINTF0 exposed so that the driver attempts to free it under incorrect ownership assumptions, resulting in the kernel freeing uninitialized or already freed resources. The primary consequence is a persistent memory/resource leak that can exhaust kernel memory or destabilize system processes.

Affected Systems

The issue affects Linux kernel builds that include the Tegra 241 IOMMU driver prior to the fix introduced in commit 1d2271d7df5230e4ce36bdafd17524bd004f3b3f. Any system running an unpatched kernel that relies on Tegra 241 hardware will be vulnerable if the driver’s init path is exercised and fails. The affected vendor is the Linux kernel itself; all distributions shipping an older kernel containing the unpatched code are potentially impacted.

Risk and Exploitability

The EPSS score is < 1 %, indicating a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. No public exploit has been reported. The description implies that an attacker who can trigger probe failures might cause a denial‑of‑service by exhausting kernel memory; this scenario is inferred from the documented behavior and is not explicitly confirmed. No CVSS score is provided, but the potential for kernel memory exhaustion suggests a medium severity impact.

Generated by OpenCVE AI on September 19, 2026 at 13:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the fix (commit 1d2271d7df5230e4ce36bdafd17524bd004f3b3f).
  • If a distribution update is not available, rebuild or patch the kernel with the Tegra IOMMU driver changes from the commit referenced above.
  • If the Tegra IOMMU driver is not required for your hardware, disable it by setting the module parameter or removing the module from initrd to avoid the flaw.
  • Monitor kernel memory usage for abnormal growth and report any suspected kernel panics that may indicate an unpatched issue.

Generated by OpenCVE AI on September 19, 2026 at 13:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-399
CWE-401

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Fix VINTF0 leak on the init-failure path tegra241_cmdqv_init_structures() allocates VINTF0 with kzalloc_obj(), inits it, and preallocates its logical VCMDQs. Two of its error paths leak. When tegra241_cmdqv_init_vintf() fails it returns before VINTF0 reaches the cmdqv->vintfs[] array, so the devres unwind on probe failure cannot reach it; free it directly there. A later VCMDQ preallocation failure instead leaves VINTF0 published, and so this time the unwind does reach tegra241_cmdqv_remove_vintf(), which then frees it from vintf->hyp_own. But tegra241_vintf_hw_init() sets that flag only afterward, from a HW read-back, so the still-uninited VINTF0 reads as guest-owned and leaks, with mutex_destroy() and ida_destroy() run on fields it never set up. Decide ownership from vintf->idx instead, the index assigned when its id is allocated: idx 0 is the kernel-owned VINTF0, while idx >= 1 marks a guest VINTF. So the in-kernel free decision in tegra241_cmdqv_remove_vintf() and tegra241_vintf_free_lvcmdq() now keys on idx too, and hyp_own stays a pure HW-readback state.
Title iommu/tegra241-cmdqv: Fix VINTF0 leak on the init-failure path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:47.165Z

Reserved: 2026-09-11T19:38:34.814Z

Link: CVE-2026-90424

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:47.060

Modified: 2026-09-17T17:17:47.060

Link: CVE-2026-90424

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:45:15Z

Weaknesses