Impact
The kernel vulnerability involves a leak of the kernel‑owned VINTF0 resource in the Tegra 241 IOMMU driver when certain initialization failures occur. When tegra241_cmdqv_init_vintf fails, the allocated VINTF0 is not added to the driver’s resource array, preventing the normal unroll of the device’s resources during probe failure and causing the memory, mutex, and IDA structures to remain allocated. Later, a failure in a preallocation step leaves the public reference to that uninitialized VINTF0 exposed so that the driver attempts to free it under incorrect ownership assumptions, resulting in the kernel freeing uninitialized or already freed resources. The primary consequence is a persistent memory/resource leak that can exhaust kernel memory or destabilize system processes.
Affected Systems
The issue affects Linux kernel builds that include the Tegra 241 IOMMU driver prior to the fix introduced in commit 1d2271d7df5230e4ce36bdafd17524bd004f3b3f. Any system running an unpatched kernel that relies on Tegra 241 hardware will be vulnerable if the driver’s init path is exercised and fails. The affected vendor is the Linux kernel itself; all distributions shipping an older kernel containing the unpatched code are potentially impacted.
Risk and Exploitability
The EPSS score is < 1 %, indicating a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. No public exploit has been reported. The description implies that an attacker who can trigger probe failures might cause a denial‑of‑service by exhausting kernel memory; this scenario is inferred from the documented behavior and is not explicitly confirmed. No CVSS score is provided, but the potential for kernel memory exhaustion suggests a medium severity impact.
OpenCVE Enrichment