Impact
The Linux kernel tegra241_cmdqv driver requests the error interrupt before it has allocated and initialized its vintfs array. If a command queue remains enabled with an error flag and a kexec is performed, the interrupt fires immediately upon request. The service routine then walks the uninitialized array, which can fault the kernel and crash the system.
Affected Systems
All Linux kernels that ship the tegra241_cmdqv driver, which is used on NVIDIA Tegra platforms. No particular kernel version is listed as fixed, so any edition containing this driver may be vulnerable until the remediation is applied.
Risk and Exploitability
The EPSS scoring is below 1% and the vulnerability is not listed in the CISA KEV catalog, signifying a low probability of exploitation. The flaw could be leveraged locally to trigger a denial‑of‑service by causing a kexec that leaves an enabled device with a latched error before the driver finishes initialization. While the theoretical attack path exists, it requires a specific device state and is unlikely to be exploited in typical deployment environments.
OpenCVE Enrichment
Debian DLA
Debian DSA