Impact
The flaw in the Linux kernel mapping for the TEGRA241 UVM driver occurs when the tegra241_cmdqv_remove function tears each virtual interrupt interface (VINTF) down before freeing its interrupt request line. This ordering mistake allows the interrupt service routine to access a stale or null‑referenced VINTF slot, resulting in a NULL pointer dereference or use‑after‑free. The kernel may crash, which can lead to a denial of service and, if the attacker controls the triggering context, could be leveraged for privilege escalation or remote code execution.
Affected Systems
The vulnerable code exists in the Linux kernel, specifically in the iommu/tegra241-cmdqv subsystem. No specific vendor or product version is listed; the issue has been remedied in later kernel releases, so any distribution that ships the kernel before the fix is potentially affected. Operating systems that use the TEGRA241 IOMMU driver – such as Jetson or other NVIDIA Tegra platforms running a standard Linux kernel – should be checked for the presence of the patch.
Risk and Exploitability
The EPSS score is below 1%, and the vulnerability is not in the CISA KEV catalog, implying low observed exploitation activity. The CVSS details are not supplied, but the nature of the bug is a kernel functional flaw that could be triggered locally by a driver user or via device interaction. An attacker with root or privileged access to the device, or one who can trigger IOMMU events, might chain the crash into broader system compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA