Description
In the Linux kernel, the following vulnerability has been resolved:

iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID

tegra241_vintf_init_vsid() maps a guest vSID to a single physical Stream ID
taken from master->streams[0], and only warns when the device does not have
exactly one stream. A device with several streams gets only its first one
mapped, so a guest vSID invalidation cannot reach the others' ATC and IOTLB
entries; a device with none makes master->streams a ZERO_SIZE_PTR, read out
of bounds.

Reject the mapping with -EOPNOTSUPP if master->num_streams is not one.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The kernel flaw occurs in the iommu/tegra241-cmdqv path where a device that offers multiple or no IOMMU streams is handled incorrectly. The code takes the first stream from the master streams array and ignores the others, or reads a zero‑size pointer when no stream is present, producing an out‑of‑bounds read that can crash the kernel. This behavior satisfies the criteria for a buffer over‑read and improper input validation weakness, and it can lead to a denial of service via a kernel crash.

Affected Systems

All Linux kernel builds that include the iommu/tegra241-cmdqv driver are affected until the patch that rejects non‑single‑stream mappings is applied. The vendor list in the advisory references only the generic Linux kernel; no product‑specific version ranges are supplied. Therefore, any kernel version before the inclusion of the fix is potentially vulnerable and should be considered for remediation.

Risk and Exploitability

With a CVSS score of 8.8 the vulnerability is high severity, but the EPSS score of < 1% indicates a very low probability of public exploitation at present. The vulnerability is not in the CISA KEV catalog. The code path that triggers the defect is reached during device initialization when an IOMMU device presents multiple or no streams, a condition that normally requires local or privileged access to configure the device or create the mapping. Consequently the attack vector is inferred to be local or privilege‑based and results in a system crash that would necessitate a reboot.

Generated by OpenCVE AI on September 20, 2026 at 01:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel patch that implements the rejection of non‑single‑stream maps in iommu/tegra241-cmdqv.
  • Confirm that all IOMMU devices on the system expose exactly one stream; if a device has multiple or no streams, reconfigure the hardware or driver or remove the device from the system.
  • Track kernel logs for EOPNOTSUPP or related iommu errors to detect re‑introduction of the flaw or misconfiguration scenarios.

Generated by OpenCVE AI on September 20, 2026 at 01:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-20

Sun, 20 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-20

Sat, 19 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-20

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID tegra241_vintf_init_vsid() maps a guest vSID to a single physical Stream ID taken from master->streams[0], and only warns when the device does not have exactly one stream. A device with several streams gets only its first one mapped, so a guest vSID invalidation cannot reach the others' ATC and IOTLB entries; a device with none makes master->streams a ZERO_SIZE_PTR, read out of bounds. Reject the mapping with -EOPNOTSUPP if master->num_streams is not one.
Title iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:19.974Z

Reserved: 2026-09-11T19:38:34.814Z

Link: CVE-2026-90425

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:47.207

Modified: 2026-09-18T18:17:58.797

Link: CVE-2026-90425

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:45:17Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-20

    Improper Input Validation