« Volver al listado

CVE-2026-90430

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized

tegra241_vintf_init_lvcmdq() stores the freshly allocated vcmdq pointer to the vintf->lvcmdqs[] array, before tegra241_vcmdq_alloc_smmu_cmdq() builds the vcmdq->cmdq. The error ISR dereferences that cmdq, so a latched LVCMDQ error (e.g. one inherited across a kexec) firing in this window would make tegra241_vintf0_handle_error() pass the still-zeroed arm_smmu_cmdq down to __arm_smmu_cmdq_skip_err(), dereferencing NULL queue register pointers.

Drop the store from tegra241_vintf_init_lvcmdq() and publish the vcmdq at the end of the allocation instead, with an smp_store_release() that pairs with an smp_load_acquire() in the ISR, which can see a fully built LVCMDQ or NULL.

Leer descripción completaMostrar menos

The user-owned LVCMDQ allocation moves accordingly, publishing the vcmdq once tegra241_vcmdq_hw_init_user() succeeds, using a plain store since a user VINTF's lvcmdqs[] has no lockless reader -- the error ISR only walks the VINTF0 array.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90430",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "918eb5c856f6ce4cf93b4b38e4b5e156905c5943",
              "lessThan": "d5ec248ee1c79354979c23f7f390e856e9535651",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "918eb5c856f6ce4cf93b4b38e4b5e156905c5943",
              "lessThan": "792f720fc23fe5bd6508d40ed73ae739debd6dcb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "918eb5c856f6ce4cf93b4b38e4b5e156905c5943",
              "lessThan": "b4535b403d6bf9bcc24dbd62096711329b9c612c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "918eb5c856f6ce4cf93b4b38e4b5e156905c5943",
              "lessThan": "cbc41aacd49e695338940196e7084770365e1b68",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.12"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.12",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:47.997",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/792f720fc23fe5bd6508d40ed73ae739debd6dcb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b4535b403d6bf9bcc24dbd62096711329b9c612c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cbc41aacd49e695338940196e7084770365e1b68",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d5ec248ee1c79354979c23f7f390e856e9535651",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized\n\ntegra241_vintf_init_lvcmdq() stores the freshly allocated vcmdq pointer to\nthe vintf->lvcmdqs[] array, before tegra241_vcmdq_alloc_smmu_cmdq() builds\nthe vcmdq->cmdq. The error ISR dereferences that cmdq, so a latched LVCMDQ\nerror (e.g. one inherited across a kexec) firing in this window would make\ntegra241_vintf0_handle_error() pass the still-zeroed arm_smmu_cmdq down to\n__arm_smmu_cmdq_skip_err(), dereferencing NULL queue register pointers.\n\nDrop the store from tegra241_vintf_init_lvcmdq() and publish the vcmdq at\nthe end of the allocation instead, with an smp_store_release() that pairs\nwith an smp_load_acquire() in the ISR, which can see a fully built LVCMDQ\nor NULL.\n\nThe user-owned LVCMDQ allocation moves accordingly, publishing the vcmdq\nonce tegra241_vcmdq_hw_init_user() succeeds, using a plain store since a\nuser VINTF's lvcmdqs[] has no lockless reader -- the error ISR only walks\nthe VINTF0 array."
    }
  ],
  "lastModified": "2026-09-21T14:17:29.013",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}