PT-2026-94777 · Linux · Linux Kernel
CVE-2026-90429
·
Published
2026-09-17
·
Updated
2026-09-28
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the iommu/tegra241-cmdqv component where the error interrupt service routine (ISR) is not properly synchronized with VINTF initialization and deinitialization. The function
tegra241 cmdqv isr() reads from the cmdqv->vintfs[] slot and dereferences the VINTF. Because there is no serialization during the teardown process in tegra241 cmdqv deinit vintf(), a concurrent error can lead to a NULL pointer dereference or a use-after-free condition. Additionally, tegra241 cmdqv init vintf() uses a plain store to publish new VINTFs, which lacks proper ordering on weakly-ordered CPUs, potentially causing the ISR to access a VINTF before its fields are fully initialized or before tegra241 vintf hw init() completes. Furthermore, the deinit vintf() function may return an index to the IDA before clearing the slot, allowing a concurrent creation process to have its new VINTF erased by a stale NULL store.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel