Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-90430

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
17/09/2026
Última modificación:
21/09/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized<br /> <br /> tegra241_vintf_init_lvcmdq() stores the freshly allocated vcmdq pointer to<br /> the vintf-&gt;lvcmdqs[] array, before tegra241_vcmdq_alloc_smmu_cmdq() builds<br /> the vcmdq-&gt;cmdq. The error ISR dereferences that cmdq, so a latched LVCMDQ<br /> error (e.g. one inherited across a kexec) firing in this window would make<br /> tegra241_vintf0_handle_error() pass the still-zeroed arm_smmu_cmdq down to<br /> __arm_smmu_cmdq_skip_err(), dereferencing NULL queue register pointers.<br /> <br /> Drop the store from tegra241_vintf_init_lvcmdq() and publish the vcmdq at<br /> the end of the allocation instead, with an smp_store_release() that pairs<br /> with an smp_load_acquire() in the ISR, which can see a fully built LVCMDQ<br /> or NULL.<br /> <br /> The user-owned LVCMDQ allocation moves accordingly, publishing the vcmdq<br /> once tegra241_vcmdq_hw_init_user() succeeds, using a plain store since a<br /> user VINTF&amp;#39;s lvcmdqs[] has no lockless reader -- the error ISR only walks<br /> the VINTF0 array.

Impacto