Impact
The vulnerability arises from a race condition in the Linux kernel’s iommu/tegra241-cmdqv driver where the interrupt service routine (ISR) accesses a VINTF structure that may be concurrently torn down or reinitialized. This can cause the ISR to read a NULL pointer or a partially initialized VINTF, leading to a null dereference or a use‑after‑free. Such kernel faults can result in a system crash or, if the fault is exploitable, privilege escalation from a compromised process. The weakness is a classic use‑after‑free scenario undermined by weak memory ordering and lack of serialization on a weakly‑ordered CPU.
Affected Systems
The issue affects the Linux kernel’s tegra241 CMDQV driver across all vendor builds that include this module. No specific kernel versions are listed in the advisory, so any deployment of the affected driver that has not yet been patched remains at risk.
Risk and Exploitability
With a CVSS score of 7.8 the flaw is considered high severity, yet its EPSS score is below 1 % and it is not currently listed in CISA’s KEV catalog, indicating low current exploitation activity. The likely attack vector is a local or privileged user that can trigger concurrent initialization and teardown of VINTF objects or generate an error interrupt while a teardown is in progress. Current evidence suggests that exploitation would require precise timing to force the ISR to read invalid memory, which is non‑trivial and would likely be mitigated by standard kernel hardening or mitigation of untrusted code.
OpenCVE Enrichment