7.4
CVE-2026-90427
- EPSS 0.12%
- Veröffentlicht 17.09.2026 16:09:49
- Zuletzt bearbeitet 18.09.2026 18:17:58
- Erkennungen
iommu/tegra241-cmdqv: Don't fall back to a freed smmu after devm_krealloc()
In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Don't fall back to a freed smmu after devm_krealloc() __tegra241_cmdqv_probe() uses devm_krealloc() to grow @smmu into the larger tegra241_cmdqv, which frees the original @smmu once it relocates. A failure after that returned NULL, and the caller then dereferenced the freed @smmu on its fallback path. Return an int and take @smmu by reference instead, then update *smmu to the reallocated pointer after devm_krealloc() succeeds, so the caller and its fallback path both use the live @smmu rather than the freed original.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
918eb5c856f6ce4cf93b4b38e4b5e156905c5943
Version <
86197679b293f0601c3331d545f99a70a7780aa9
Status
affected
Version
918eb5c856f6ce4cf93b4b38e4b5e156905c5943
Version <
d4d05f55e9da646ec03adfa77260eb46f4163749
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.12
Status
affected
Version
0
Version <
6.12
Status
unaffected
Version <=
7.2.*
Version
7.2.6
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.02 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.4 | 1.4 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/86197679b293f0601c3331d545f99a70a7780aa9
https://git.kernel.org/stable/c/d4d05f55e9da646ec03adfa77260eb46f4163749