← Back to CVE List
CVE-2026-90427NVD
Vulnerability Summary
In the Linux kernel, the following vulnerability has been resolved:
iommu/tegra241-cmdqv: Don't fall back to a freed smmu after devm_krealloc()
__tegra241_cmdqv_probe() uses devm_krealloc() to grow @smmu into the larger
tegra241_cmdqv, which frees the original @smmu once it relocates. A failure
after that returned NULL, and the caller then dereferenced the freed @smmu
on its fallback path.
Return an int and take @smmu by reference instead, then update *smmu to the
reallocated pointer after devm_krealloc() succeeds, so the caller and its
fallback path both use the live @smmu rather than the freed original.
iommu/tegra241-cmdqv: Don't fall back to a freed smmu after devm_krealloc()
__tegra241_cmdqv_probe() uses devm_krealloc() to grow @smmu into the larger
tegra241_cmdqv, which frees the original @smmu once it relocates. A failure
after that returned NULL, and the caller then dereferenced the freed @smmu
on its fallback path.
Return an int and take @smmu by reference instead, then update *smmu to the
reallocated pointer after devm_krealloc() succeeds, so the caller and its
fallback path both use the live @smmu rather than the freed original.
CVSS v3.1 Base Metrics — Score 7.4 (HIGH)
Attack VectorLocal
Attack ComplexityHigh
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Linux Linux >= 918eb5c856f6ce4cf93b4b38e4b5e156905c5943 and < 86197679b293f0601c3331d545f99a70a7780aa9
- Linux Linux >= 918eb5c856f6ce4cf93b4b38e4b5e156905c5943 and < d4d05f55e9da646ec03adfa77260eb46f4163749
- Linux Linux >= 6.12
- Linux Linux 86197679b293f0601c3331d545f99a70a7780aa9
- Linux Linux d4d05f55e9da646ec03adfa77260eb46f4163749