Description
In the Linux kernel, the following vulnerability has been resolved:

iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized

tegra241_vintf_init_lvcmdq() stores the freshly allocated vcmdq pointer to
the vintf->lvcmdqs[] array, before tegra241_vcmdq_alloc_smmu_cmdq() builds
the vcmdq->cmdq. The error ISR dereferences that cmdq, so a latched LVCMDQ
error (e.g. one inherited across a kexec) firing in this window would make
tegra241_vintf0_handle_error() pass the still-zeroed arm_smmu_cmdq down to
__arm_smmu_cmdq_skip_err(), dereferencing NULL queue register pointers.

Drop the store from tegra241_vintf_init_lvcmdq() and publish the vcmdq at
the end of the allocation instead, with an smp_store_release() that pairs
with an smp_load_acquire() in the ISR, which can see a fully built LVCMDQ
or NULL.

The user-owned LVCMDQ allocation moves accordingly, publishing the vcmdq
once tegra241_vcmdq_hw_init_user() succeeds, using a plain store since a
user VINTF's lvcmdqs[] has no lockless reader -- the error ISR only walks
the VINTF0 array.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel crash (Denial of Service)
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel tegra241 driver contains a race that publishes a virtual command queue (vcmdq) before the underlying command queue structure is fully built. An error interrupt service routine can fire while this incomplete pointer is visible, dereferencing a zeroed or NULL structure and causing a kernel panic. The failure results in a system crash and loss of service. The weakness is identified as a null pointer dereference (CWE‑476).

Affected Systems

Affected boots are Linux kernel builds that include the tegra241 platform driver, typically used on NVIDIA Tegra SoC devices. Any kernel that compiles the tegra241 driver before the fix—identified by the commit that moves vcmdq publishing to after full initialization—may crash when the error ISR occurs. Specific version numbers are not listed, so all pre‑fix kernels are vulnerable.

Risk and Exploitability

The EPSS score of <1% indicates that exploitation probability is low. The vulnerability is not listed in CISA’s KEV catalog. Exploitation would likely require a local kernel scenario that can trigger the error ISR during the brief window when the vcmdq is not yet fully constructed, such as during boot or a forced kexec operation. Overall risk is moderate; a kernel crash leads to downtime and potential data loss.

Generated by OpenCVE AI on September 19, 2026 at 12:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that includes the tegra241 driver fix or backport the specific commit (e.g., 792f720fc23fe5bd6508d40ed73ae739debd6dcb) from the official repository.
  • Reboot the device to load the updated kernel and ensure the patch is active.
  • If a patch cannot be applied immediately, enable detailed kernel logging to capture LVCMDQ error messages and avoid operations (such as kexec or hardware resets) that may trigger the ISR during early boot until the fix is in place.

Generated by OpenCVE AI on September 19, 2026 at 12:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 13:30:00 +0000


Sat, 19 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized tegra241_vintf_init_lvcmdq() stores the freshly allocated vcmdq pointer to the vintf->lvcmdqs[] array, before tegra241_vcmdq_alloc_smmu_cmdq() builds the vcmdq->cmdq. The error ISR dereferences that cmdq, so a latched LVCMDQ error (e.g. one inherited across a kexec) firing in this window would make tegra241_vintf0_handle_error() pass the still-zeroed arm_smmu_cmdq down to __arm_smmu_cmdq_skip_err(), dereferencing NULL queue register pointers. Drop the store from tegra241_vintf_init_lvcmdq() and publish the vcmdq at the end of the allocation instead, with an smp_store_release() that pairs with an smp_load_acquire() in the ISR, which can see a fully built LVCMDQ or NULL. The user-owned LVCMDQ allocation moves accordingly, publishing the vcmdq once tegra241_vcmdq_hw_init_user() succeeds, using a plain store since a user VINTF's lvcmdqs[] has no lockless reader -- the error ISR only walks the VINTF0 array.
Title iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:15:23.757Z

Reserved: 2026-09-11T19:38:34.815Z

Link: CVE-2026-90430

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:47.997

Modified: 2026-09-21T14:17:29.013

Link: CVE-2026-90430

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:00:11Z

Weaknesses