Impact
The kernel flaw occurs in the iommu/tegra241-cmdqv path where a device that offers multiple or no IOMMU streams is handled incorrectly. The code takes the first stream from the master streams array and ignores the others, or reads a zero‑size pointer when no stream is present, producing an out‑of‑bounds read that can crash the kernel. This behavior satisfies the criteria for a buffer over‑read and improper input validation weakness, and it can lead to a denial of service via a kernel crash.
Affected Systems
All Linux kernel builds that include the iommu/tegra241-cmdqv driver are affected until the patch that rejects non‑single‑stream mappings is applied. The vendor list in the advisory references only the generic Linux kernel; no product‑specific version ranges are supplied. Therefore, any kernel version before the inclusion of the fix is potentially vulnerable and should be considered for remediation.
Risk and Exploitability
With a CVSS score of 8.8 the vulnerability is high severity, but the EPSS score of < 1% indicates a very low probability of public exploitation at present. The vulnerability is not in the CISA KEV catalog. The code path that triggers the defect is reached during device initialization when an IOMMU device presents multiple or no streams, a condition that normally requires local or privileged access to configure the device or create the mapping. Consequently the attack vector is inferred to be local or privilege‑based and results in a system crash that would necessitate a reboot.
OpenCVE Enrichment