PT-2026-94777 · Linux · Linux Kernel

CVE-2026-90429

·

Published

2026-09-17

·

Updated

2026-09-28

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the iommu/tegra241-cmdqv component where the error interrupt service routine (ISR) is not properly synchronized with VINTF initialization and deinitialization. The function tegra241 cmdqv isr() reads from the cmdqv->vintfs[] slot and dereferences the VINTF. Because there is no serialization during the teardown process in tegra241 cmdqv deinit vintf(), a concurrent error can lead to a NULL pointer dereference or a use-after-free condition. Additionally, tegra241 cmdqv init vintf() uses a plain store to publish new VINTFs, which lacks proper ordering on weakly-ordered CPUs, potentially causing the ISR to access a VINTF before its fields are fully initialized or before tegra241 vintf hw init() completes. Furthermore, the deinit vintf() function may return an index to the IDA before clearing the slot, allowing a concurrent creation process to have its new VINTF erased by a stale NULL store.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-90429
OPENSUSE-SU-2026:11893-1

Affected Products

Linux Kernel