Description
In the Linux kernel, the following vulnerability has been resolved:

iommu/tegra241-cmdqv: Don't fall back to a freed smmu after devm_krealloc()

__tegra241_cmdqv_probe() uses devm_krealloc() to grow @smmu into the larger
tegra241_cmdqv, which frees the original @smmu once it relocates. A failure
after that returned NULL, and the caller then dereferenced the freed @smmu
on its fallback path.

Return an int and take @smmu by reference instead, then update *smmu to the
reallocated pointer after devm_krealloc() succeeds, so the caller and its
fallback path both use the live @smmu rather than the freed original.
Published: 2026-09-17
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption that may lead to privilege escalation
Action: Immediate Patch
AI Analysis

Impact

A use‑after‑free occurs in the iommu tegra241 cmdqv probe routine when the smmu structure is reallocated with devm_krealloc. If the reallocation fails, the original pointer is freed and the fallback code later dereferences this freed address. This kernel memory corruption can cause a crash or provide a foothold for an attacker to gain elevated privileges. The vulnerability is a classic use‑after‑free flaw.

Affected Systems

The flaw resides in the Linux kernel’s tegra241 cmdqv IOMMU driver. Any kernel image that contains this driver – typically used on NVIDIA Tegra platforms – is affected. No specific kernel version ranges are listed, but the patch is available in recent kernel releases since the referenced commits.

Risk and Exploitability

The CVSS score of 7.4 indicates high severity. The EPSS score of less than 1% reflects a low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is local: an attacker with the ability to load or reinitialize the device (e.g., via udev or system startup) can trigger the probe path and cause the use‑after‑free. Remote exploitation without additional vulnerabilities is not indicated by the available data.

Generated by OpenCVE AI on September 20, 2026 at 00:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that incorporates commit 86197679b293f0601c3331d545f99a70a7780aa9 and its follow‑up fix d4d05f55e9da646ec03adfa77260eb46f4163749, which resolve the use‑after‑free.
  • If an immediate kernel upgrade is not possible, prevent the tegra241 cmdqv driver from loading by disabling the relevant device node or blocking its auto‑probe via udev rules, or by setting kernel parameters that disable IOMMU driver initialization for that platform.
  • As a fallback, consider restoring a kernel version compiled without the tegra241 cmdqv code or applying the patch to a custom kernel build before deployment.

Generated by OpenCVE AI on September 20, 2026 at 00:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Don't fall back to a freed smmu after devm_krealloc() __tegra241_cmdqv_probe() uses devm_krealloc() to grow @smmu into the larger tegra241_cmdqv, which frees the original @smmu once it relocates. A failure after that returned NULL, and the caller then dereferenced the freed @smmu on its fallback path. Return an int and take @smmu by reference instead, then update *smmu to the reallocated pointer after devm_krealloc() succeeds, so the caller and its fallback path both use the live @smmu rather than the freed original.
Title iommu/tegra241-cmdqv: Don't fall back to a freed smmu after devm_krealloc()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:21.334Z

Reserved: 2026-09-11T19:38:34.814Z

Link: CVE-2026-90427

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:47.500

Modified: 2026-09-18T18:17:58.930

Link: CVE-2026-90427

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:30:16Z

Weaknesses