Impact
A use‑after‑free occurs in the iommu tegra241 cmdqv probe routine when the smmu structure is reallocated with devm_krealloc. If the reallocation fails, the original pointer is freed and the fallback code later dereferences this freed address. This kernel memory corruption can cause a crash or provide a foothold for an attacker to gain elevated privileges. The vulnerability is a classic use‑after‑free flaw.
Affected Systems
The flaw resides in the Linux kernel’s tegra241 cmdqv IOMMU driver. Any kernel image that contains this driver – typically used on NVIDIA Tegra platforms – is affected. No specific kernel version ranges are listed, but the patch is available in recent kernel releases since the referenced commits.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity. The EPSS score of less than 1% reflects a low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is local: an attacker with the ability to load or reinitialize the device (e.g., via udev or system startup) can trigger the probe path and cause the use‑after‑free. Remote exploitation without additional vulnerabilities is not indicated by the available data.
OpenCVE Enrichment