8.8

CVE-2026-89450

iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field

In the Linux kernel, the following vulnerability has been resolved:

iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field

tegra241_vintf_init_vsid() programs the guest-provided vSID into SID_MATCH,
whose VIRT_SID field spans bits [20:1] with bit 0 as the match-enable flag.
The HW therefore matches only a 20-bit Stream ID.

The bound check rejects only virt_sid > UINT_MAX, which admits a value far
wider than the field. The write "virt_sid << 1 | 0x1" then drops every bit
above 20: a virt_sid of 0x80000000 lands as SID_MATCH = 0x1, a valid match
on vSID 0, so the entry aliases the wrong Stream ID. Because vdev->virt_id
is guest-controlled, a VMM can trigger it.

Validate virt_sid against the field width with FIELD_MAX(), and program the
register with FIELD_PREP() so the value and the field stay consistent.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7
Version < d903d99ffd22b0180bd745a43f221c21bcdd8d7c
Status affected
Version 4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7
Version < 445204550f894ca325ac80a21e3df177ad073798
Status affected
Version 4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7
Version < 4379610c79bd88ddbea10e7f6c21e16d4b338c6b
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.17
Status affected
Version 0
Version < 6.17
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.027
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2 6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/d903d99ffd22b0180bd745a43f221c21bcdd8d7c
https://git.kernel.org/stable/c/445204550f894ca325ac80a21e3df177ad073798
https://git.kernel.org/stable/c/4379610c79bd88ddbea10e7f6c21e16d4b338c6b