Description
In the Linux kernel, the following vulnerability has been resolved:

iommu/tegra241-cmdqv: Don't run the error ISR before probe sets up vintfs

__tegra241_cmdqv_probe() requests the error IRQ before it has allocated the
cmdqv->vintfs array and set cmdqv->num_vintfs. A CMDQV left enabled with a
latched error across a kexec fires the IRQ as soon as it is requested, and
tegra241_cmdqv_isr() then walks the uninitialized cmdqv->vintfs array.

Request the IRQ only after cmdqv->vintfs is allocated and zeroed, so that
a latched interrupt firing early runs the ISR against a valid array of NULL
slots that it safely skips.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (kernel crash)
Action: Apply Patch
AI Analysis

Impact

The Linux kernel tegra241_cmdqv driver requests the error interrupt before it has allocated and initialized its vintfs array. If a command queue remains enabled with an error flag and a kexec is performed, the interrupt fires immediately upon request. The service routine then walks the uninitialized array, which can fault the kernel and crash the system.

Affected Systems

All Linux kernels that ship the tegra241_cmdqv driver, which is used on NVIDIA Tegra platforms. No particular kernel version is listed as fixed, so any edition containing this driver may be vulnerable until the remediation is applied.

Risk and Exploitability

The EPSS scoring is below 1% and the vulnerability is not listed in the CISA KEV catalog, signifying a low probability of exploitation. The flaw could be leveraged locally to trigger a denial‑of‑service by causing a kexec that leaves an enabled device with a latched error before the driver finishes initialization. While the theoretical attack path exists, it requires a specific device state and is unlikely to be exploited in typical deployment environments.

Generated by OpenCVE AI on September 19, 2026 at 05:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to the latest release that incorporates the fix where the error interrupt is requested only after the vintfs array is allocated and zeroed.
  • If an immediate kernel upgrade is not feasible, disable the CMDQV error interrupt or disable the tegra241 device entirely until driver initialization is completed.
  • Ensure that any kexec operations cleanly reset or disable the device to avoid holding a latched error before reboot.
  • Monitor vendor advisories for additional guidance or temporary workarounds.

Generated by OpenCVE AI on September 19, 2026 at 05:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Don't run the error ISR before probe sets up vintfs __tegra241_cmdqv_probe() requests the error IRQ before it has allocated the cmdqv->vintfs array and set cmdqv->num_vintfs. A CMDQV left enabled with a latched error across a kexec fires the IRQ as soon as it is requested, and tegra241_cmdqv_isr() then walks the uninitialized cmdqv->vintfs array. Request the IRQ only after cmdqv->vintfs is allocated and zeroed, so that a latched interrupt firing early runs the ISR against a valid array of NULL slots that it safely skips.
Title iommu/tegra241-cmdqv: Don't run the error ISR before probe sets up vintfs
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:49.783Z

Reserved: 2026-09-11T19:38:34.814Z

Link: CVE-2026-90428

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:47.643

Modified: 2026-09-17T17:17:47.643

Link: CVE-2026-90428

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T08:45:06Z

Weaknesses