Executive brief
A vulnerability was identified in the Linux kernel's support for NVIDIA Tegra processors. The issue involves a technical error in how the system looks up internal hardware communication paths, which could lead to an unstable system or unexpected behavior. This primarily affects devices using Tegra chips, such as certain embedded systems or automotive platforms.
Technical details
An out-of-bounds (OOB) access vulnerability exists in `drivers/soc/tegra/cbb/tegra234-cbb.c` within the Linux kernel. The root cause is the incorrect use of the `ARRAY_SIZE` macro in the `tegra234_cbb_fab_list` and `tegra241_cbb_fab_list` lookup tables, where the size of one fabric map was incorrectly used for another. This can lead to an out-of-bounds read during target timeout lookups. The issue affects Tegra234 and Tegra241 SoCs. Patches have been released in various stable branches including 6.18.33 and 7.0.10.
Affected products
- Linux Linux Kernel 6.17 to 6.18.33, 7.0 to 7.0.10
Timeline
- 2026-01-21: other: Vulnerability fixed in source code
- 2026-06-24: disclosed: CVE published