iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs
Summary
| CVE | CVE-2026-90426 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-17 17:17:47 UTC |
| Updated | 2026-09-17 17:17:47 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs
tegra241_cmdqv_remove() tears each VINTF down first, then calls free_irq().
Tearing a VINTF down frees vintf0 and clears cmdqv->vintfs[0]. An error in
that window makes tegra241_cmdqv_isr() read the stale slot and hand it to
tegra241_vintf0_handle_error(), which dereferences a NULL or freed pointer.
Free the IRQ before tearing the VINTFs down. free_irq() waits for in-flight
handlers to finish and blocks new ones, so no ISR can observe a VINTF as it
is torn down.
Note: a user-owned VINTF (viommu) could outlive this teardown, which unmaps
cmdqv->base and frees cmdqv->vintfs, so a later viommu close then touches
freed memory. This is neither introduced nor fixed here: a physical IOMMU
is not a pluggable device, so iommufd by design holds no reference on the
one behind a viommu, and this teardown is not expected while that viommu is
still alive. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 918eb5c856f6ce4cf93b4b38e4b5e156905c5943 076a4f5b1fc2016b973a12bc2ebb9b730e5e1e48 git |
Not specified |
| CNA |
Linux |
Linux |
affected 918eb5c856f6ce4cf93b4b38e4b5e156905c5943 735698e81f798b4c02dcb6291ffbdd1b962c8c66 git |
Not specified |
| CNA |
Linux |
Linux |
affected 918eb5c856f6ce4cf93b4b38e4b5e156905c5943 421f5ab135cd4a1353891e5bf2602cfc3c01afc7 git |
Not specified |
| CNA |
Linux |
Linux |
affected 918eb5c856f6ce4cf93b4b38e4b5e156905c5943 61f0d437988e5730b04442f6a7d30a9907339f2a git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.12 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.110 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.52 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.6 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/076a4f5b1fc2016b973a12bc2ebb9b730e5e1e48 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/735698e81f798b4c02dcb6291ffbdd1b962c8c66 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/61f0d437988e5730b04442f6a7d30a9907339f2a |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/421f5ab135cd4a1353891e5bf2602cfc3c01afc7 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.