« Volver al listado

CVE-2026-90429

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

iommu/tegra241-cmdqv: Synchronize the error ISR against VINTF (de)init

A user VINTF is torn down by tegra241_cmdqv_deinit_vintf(), which runs from the destroy callback and from the init-failure unwind in the alloc handler. It clears the cmdqv->vintfs[] slot and lets the iommufd core free it, but nothing serializes that against the error interrupt: tegra241_cmdqv_isr() reads cmdqv->vintfs[idx] and dereferences the vintf. A concurrent error can make the ISR read a slot mid-clear (a NULL deref) or use a vintf which is about to be freed (a use-after-free).

Leer descripción completaMostrar menos

deinit_vintf() also returns idx to the IDA before clearing the slot, so a concurrent create that reuses idx can publish its new vintf into the slot, only for this teardown to erase it again with the stale NULL store.

On the other end, tegra241_cmdqv_init_vintf() publishes a new vintf with a plain store to the cmdqv->vintfs[] slot, and the ISR dereferences fields of a published vintf such as vintf->base. A plain store gives no ordering on a weakly-ordered CPU, and a stale VINTF_ERR_MAP bit on a reused idx can make the ISR pick a vintf the moment it is published, before its fields are set or tegra241_vintf_hw_init() runs.

The cmdqv->vintfs[0] slot stays NULL until tegra241_cmdqv_init_structures() first creates VINTF0, so the slot 0 read needs the same NULL check.

Publish every slot with an smp_store_release(), and read each slot in the ISR with an smp_load_acquire() under a NULL check, so the ISR always sees a fully built vintf or NULL. Also make deinit_vintf() clear the slot, and synchronize_irq() prior to returning idx to the IDA, so no vintf is freed under a running handler and no reused idx is clobbered.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de race condition en kernel Linux (AV:L, PR:L) que causa NULL deref y use-after-free en manejador de interrupciones; permite DoS local mediante acceso sin privilegios elevados.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90429",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7",
              "lessThan": "bcb82407633c3008362ad927699d985ee4981557",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7",
              "lessThan": "f3ef4abc271a1d3d7b6715879e149c286dc8aae7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7",
              "lessThan": "a491be376abd1c80a314cdd658632c85cd660b73",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.17"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.17",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:47.850",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/a491be376abd1c80a314cdd658632c85cd660b73",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bcb82407633c3008362ad927699d985ee4981557",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f3ef4abc271a1d3d7b6715879e149c286dc8aae7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/tegra241-cmdqv: Synchronize the error ISR against VINTF (de)init\n\nA user VINTF is torn down by tegra241_cmdqv_deinit_vintf(), which runs from\nthe destroy callback and from the init-failure unwind in the alloc handler.\nIt clears the cmdqv->vintfs[] slot and lets the iommufd core free it, but\nnothing serializes that against the error interrupt: tegra241_cmdqv_isr()\nreads cmdqv->vintfs[idx] and dereferences the vintf. A concurrent error can\nmake the ISR read a slot mid-clear (a NULL deref) or use a vintf which is\nabout to be freed (a use-after-free).\n\ndeinit_vintf() also returns idx to the IDA before clearing the slot, so a\nconcurrent create that reuses idx can publish its new vintf into the slot,\nonly for this teardown to erase it again with the stale NULL store.\n\nOn the other end, tegra241_cmdqv_init_vintf() publishes a new vintf with a\nplain store to the cmdqv->vintfs[] slot, and the ISR dereferences fields of\na published vintf such as vintf->base. A plain store gives no ordering on a\nweakly-ordered CPU, and a stale VINTF_ERR_MAP bit on a reused idx can make\nthe ISR pick a vintf the moment it is published, before its fields are set\nor tegra241_vintf_hw_init() runs.\n\nThe cmdqv->vintfs[0] slot stays NULL until tegra241_cmdqv_init_structures()\nfirst creates VINTF0, so the slot 0 read needs the same NULL check.\n\nPublish every slot with an smp_store_release(), and read each slot in the\nISR with an smp_load_acquire() under a NULL check, so the ISR always sees\na fully built vintf or NULL. Also make deinit_vintf() clear the slot, and\nsynchronize_irq() prior to returning idx to the IDA, so no vintf is freed\nunder a running handler and no reused idx is clobbered."
    }
  ],
  "lastModified": "2026-09-18T18:17:59.077",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}