Junglewise Threat Intelligence

CVE-2026-90424: Linux kernel IOMMU Tegra241 VINTF0 resource leak on init failure

CVE-2026-90424 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's IOMMU driver for NVIDIA Tegra241 processors contains resource leaks when virtual interface (VINTF0) initialization fails. Under error conditions during system startup, memory and data structures allocated for the IOMMU's command queue are not properly freed, potentially leading to memory exhaustion or system instability.

Technical details

The vulnerability is a resource leak in the tegra241_cmdqv_init_structures() function within drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c. Two error paths fail to free allocated VINTF0 structures: when tegra241_cmdqv_init_vintf() fails, VINTF0 is allocated but never published to the cmdqv->vintfs[] array, preventing devres cleanup; when VCMDQ preallocation fails later, VINTF0 is already published but the ownership detection via hyp_own flag may be incorrect, causing the cleanup path to execute mutex_destroy() and ida_destroy() on uninitialized fields. The fix changes ownership detection to use vintf->idx (0 for kernel-owned VINTF0, ≥1 for guest VINTFs) instead of reading the hyp_own hardware state, ensuring proper cleanup decisions. The vulnerability requires kernel initialization to trigger and affects all systems using Tegra241 with IOMMU support.

Affected products

  • Linux Linux kernel all versions with commit 918eb5c856f6 (NVIDIA Tegra241 CMDQV support) and before the fix

Timeline

  • 2026-09-17: disclosed: CVE-2026-90424 published
  • 2026-09-14: patched: Fix committed to stable kernel trees by Greg Kroah-Hartman

References

Related threats