← Back to CVE List
CVE-2026-90425NVD
Vulnerability Summary
In the Linux kernel, the following vulnerability has been resolved:
iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID
tegra241_vintf_init_vsid() maps a guest vSID to a single physical Stream ID
taken from master->streams[0], and only warns when the device does not have
exactly one stream. A device with several streams gets only its first one
mapped, so a guest vSID invalidation cannot reach the others' ATC and IOTLB
entries; a device with none makes master->streams a ZERO_SIZE_PTR, read out
of bounds.
Reject the mapping with -EOPNOTSUPP if master->num_streams is not one.
iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID
tegra241_vintf_init_vsid() maps a guest vSID to a single physical Stream ID
taken from master->streams[0], and only warns when the device does not have
exactly one stream. A device with several streams gets only its first one
mapped, so a guest vSID invalidation cannot reach the others' ATC and IOTLB
entries; a device with none makes master->streams a ZERO_SIZE_PTR, read out
of bounds.
Reject the mapping with -EOPNOTSUPP if master->num_streams is not one.
CVSS v3.1 Base Metrics — Score 8.8 (HIGH)
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Linux Linux >= 4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7 and < 9b37afb2d34d99ec4f8db28134181b5a8ec9a4a5
- Linux Linux >= 4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7 and < 0b139ec4641c7d4163d8e345c26cc630e24fa43b
- Linux Linux >= 4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7 and < fb292bfc9be936dade7eef7ec5762de1201983d8
- Linux Linux >= 6.17
- Linux Linux 9b37afb2d34d99ec4f8db28134181b5a8ec9a4a5
- Linux Linux 0b139ec4641c7d4163d8e345c26cc630e24fa43b
- Linux Linux fb292bfc9be936dade7eef7ec5762de1201983d8