Description
In the Linux kernel, the following vulnerability has been resolved:

iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs

tegra241_cmdqv_remove() tears each VINTF down first, then calls free_irq().
Tearing a VINTF down frees vintf0 and clears cmdqv->vintfs[0]. An error in
that window makes tegra241_cmdqv_isr() read the stale slot and hand it to
tegra241_vintf0_handle_error(), which dereferences a NULL or freed pointer.

Free the IRQ before tearing the VINTFs down. free_irq() waits for in-flight
handlers to finish and blocks new ones, so no ISR can observe a VINTF as it
is torn down.

Note: a user-owned VINTF (viommu) could outlive this teardown, which unmaps
cmdqv->base and frees cmdqv->vintfs, so a later viommu close then touches
freed memory. This is neither introduced nor fixed here: a physical IOMMU
is not a pluggable device, so iommufd by design holds no reference on the
one behind a viommu, and this teardown is not expected while that viommu is
still alive.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (kernel crash leading to possible privilege escalation)
Action: Apply Patch
AI Analysis

Impact

The flaw in the Linux kernel mapping for the TEGRA241 UVM driver occurs when the tegra241_cmdqv_remove function tears each virtual interrupt interface (VINTF) down before freeing its interrupt request line. This ordering mistake allows the interrupt service routine to access a stale or null‑referenced VINTF slot, resulting in a NULL pointer dereference or use‑after‑free. The kernel may crash, which can lead to a denial of service and, if the attacker controls the triggering context, could be leveraged for privilege escalation or remote code execution.

Affected Systems

The vulnerable code exists in the Linux kernel, specifically in the iommu/tegra241-cmdqv subsystem. No specific vendor or product version is listed; the issue has been remedied in later kernel releases, so any distribution that ships the kernel before the fix is potentially affected. Operating systems that use the TEGRA241 IOMMU driver – such as Jetson or other NVIDIA Tegra platforms running a standard Linux kernel – should be checked for the presence of the patch.

Risk and Exploitability

The EPSS score is below 1%, and the vulnerability is not in the CISA KEV catalog, implying low observed exploitation activity. The CVSS details are not supplied, but the nature of the bug is a kernel functional flaw that could be triggered locally by a driver user or via device interaction. An attacker with root or privileged access to the device, or one who can trigger IOMMU events, might chain the crash into broader system compromise.

Generated by OpenCVE AI on September 19, 2026 at 05:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that incorporates the tegra241_cmdqv_remove fix; the change is present in commit 076a4f5b1fc2016b973a12bc2ebb9b730e5e1e48 and later releases.
  • If the operating system cannot be upgraded immediately, remove or disable the tegra241_cmdqv driver module to eliminate the attack surface, ensuring no VINTF teardown occurs.
  • After updating or disabling, monitor kernel logs for IOMMU related errors and verify that the driver loads correctly; if errors persist, re‑apply the patch or consult the vendor for a newer kernel build.

Generated by OpenCVE AI on September 19, 2026 at 05:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs tegra241_cmdqv_remove() tears each VINTF down first, then calls free_irq(). Tearing a VINTF down frees vintf0 and clears cmdqv->vintfs[0]. An error in that window makes tegra241_cmdqv_isr() read the stale slot and hand it to tegra241_vintf0_handle_error(), which dereferences a NULL or freed pointer. Free the IRQ before tearing the VINTFs down. free_irq() waits for in-flight handlers to finish and blocks new ones, so no ISR can observe a VINTF as it is torn down. Note: a user-owned VINTF (viommu) could outlive this teardown, which unmaps cmdqv->base and frees cmdqv->vintfs, so a later viommu close then touches freed memory. This is neither introduced nor fixed here: a physical IOMMU is not a pluggable device, so iommufd by design holds no reference on the one behind a viommu, and this teardown is not expected while that viommu is still alive.
Title iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:48.460Z

Reserved: 2026-09-11T19:38:34.814Z

Link: CVE-2026-90426

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:47.353

Modified: 2026-09-17T17:17:47.353

Link: CVE-2026-90426

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T08:45:06Z

Weaknesses