-

CVE-2026-90430

iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized

In the Linux kernel, the following vulnerability has been resolved:

iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized

tegra241_vintf_init_lvcmdq() stores the freshly allocated vcmdq pointer to
the vintf->lvcmdqs[] array, before tegra241_vcmdq_alloc_smmu_cmdq() builds
the vcmdq->cmdq. The error ISR dereferences that cmdq, so a latched LVCMDQ
error (e.g. one inherited across a kexec) firing in this window would make
tegra241_vintf0_handle_error() pass the still-zeroed arm_smmu_cmdq down to
__arm_smmu_cmdq_skip_err(), dereferencing NULL queue register pointers.

Drop the store from tegra241_vintf_init_lvcmdq() and publish the vcmdq at
the end of the allocation instead, with an smp_store_release() that pairs
with an smp_load_acquire() in the ISR, which can see a fully built LVCMDQ
or NULL.

The user-owned LVCMDQ allocation moves accordingly, publishing the vcmdq
once tegra241_vcmdq_hw_init_user() succeeds, using a plain store since a
user VINTF's lvcmdqs[] has no lockless reader -- the error ISR only walks
the VINTF0 array.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 918eb5c856f6ce4cf93b4b38e4b5e156905c5943
Version < d5ec248ee1c79354979c23f7f390e856e9535651
Status affected
Version 918eb5c856f6ce4cf93b4b38e4b5e156905c5943
Version < 792f720fc23fe5bd6508d40ed73ae739debd6dcb
Status affected
Version 918eb5c856f6ce4cf93b4b38e4b5e156905c5943
Version < b4535b403d6bf9bcc24dbd62096711329b9c612c
Status affected
Version 918eb5c856f6ce4cf93b4b38e4b5e156905c5943
Version < cbc41aacd49e695338940196e7084770365e1b68
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.12
Status affected
Version 0
Version < 6.12
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.099
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/792f720fc23fe5bd6508d40ed73ae739debd6dcb
https://git.kernel.org/stable/c/b4535b403d6bf9bcc24dbd62096711329b9c612c
https://git.kernel.org/stable/c/cbc41aacd49e695338940196e7084770365e1b68
https://git.kernel.org/stable/c/d5ec248ee1c79354979c23f7f390e856e9535651