- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:09:51
- Zuletzt bearbeitet 21.09.2026 14:17:29
In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized tegra241_vintf_init_lvcmdq() stores the freshly allocated vcmdq pointer to the vintf->lvcmdqs[] array, be...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:09:51
- Zuletzt bearbeitet 17.09.2026 17:17:48
In the Linux kernel, the following vulnerability has been resolved: remoteproc: Prevent crash handling to race with rproc_del() There's no synchronization between rproc_crash_handler_work() and rproc_del(), as such it's possible for a driver to be ...
CVE-2026-90429
- EPSS 0.16%
- Veröffentlicht 17.09.2026 16:09:50
- Zuletzt bearbeitet 18.09.2026 18:17:59
In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Synchronize the error ISR against VINTF (de)init A user VINTF is torn down by tegra241_cmdqv_deinit_vintf(), which runs from the destroy callback and from the...
CVE-2026-90427
- EPSS 0.12%
- Veröffentlicht 17.09.2026 16:09:49
- Zuletzt bearbeitet 18.09.2026 18:17:58
In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Don't fall back to a freed smmu after devm_krealloc() __tegra241_cmdqv_probe() uses devm_krealloc() to grow @smmu into the larger tegra241_cmdqv, which frees ...
- EPSS 0.17%
- Veröffentlicht 17.09.2026 16:09:49
- Zuletzt bearbeitet 17.09.2026 17:17:47
In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Don't run the error ISR before probe sets up vintfs __tegra241_cmdqv_probe() requests the error IRQ before it has allocated the cmdqv->vintfs array and set cm...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:09:48
- Zuletzt bearbeitet 17.09.2026 17:17:47
In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs tegra241_cmdqv_remove() tears each VINTF down first, then calls free_irq(). Tearing a VINTF down frees vintf0 an...
- EPSS 0.17%
- Veröffentlicht 17.09.2026 16:09:47
- Zuletzt bearbeitet 17.09.2026 17:17:47
In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Fix VINTF0 leak on the init-failure path tegra241_cmdqv_init_structures() allocates VINTF0 with kzalloc_obj(), inits it, and preallocates its logical VCMDQs. ...
CVE-2026-90425
- EPSS 0.13%
- Veröffentlicht 17.09.2026 16:09:47
- Zuletzt bearbeitet 18.09.2026 18:17:58
In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID tegra241_vintf_init_vsid() maps a guest vSID to a single physical Stream ID taken from master->streams[0], and only w...
CVE-2026-90423
- EPSS 0.13%
- Veröffentlicht 17.09.2026 16:09:46
- Zuletzt bearbeitet 18.09.2026 18:17:58
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix UAF in ODP init error-handling path rxe_odp_mr_init_user() stores &umem_odp->umem in mr->umem before calling rxe_odp_init_pages(). If rxe_odp_init_pages() fails, rxe_...
- EPSS 0.19%
- Veröffentlicht 17.09.2026 16:09:45
- Zuletzt bearbeitet 17.09.2026 17:17:46
In the Linux kernel, the following vulnerability has been resolved: PCI: Fix UAF when probe runs concurrent to dyn ID removal Dynamic IDs are only guaranteed to be valid when dynids.lock is held, as remove_id_store() can free the node. Thus, make a...