CVE-2026-89450

Summary

In the Linux kernel, the following vulnerability has been resolved:

iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field

tegra241_vintf_init_vsid() programs the guest-provided vSID into SID_MATCH, whose VIRT_SID field spans bits [20:1] with bit 0 as the match-enable flag. The HW therefore matches only a 20-bit Stream ID.

The bound check rejects only virt_sid > UINT_MAX, which admits a value far wider than the field. The write "virt_sid << 1 | 0x1" then drops every bit above 20: a virt_sid of 0x80000000 lands as SID_MATCH = 0x1, a valid match on vSID 0, so the entry aliases the wrong Stream ID. Because vdev->virt_id is guest-controlled, a VMM can trigger it.

Validate virt_sid against the field width with FIELD_MAX(), and program the register with FIELD_PREP() so the value and the field stay consistent.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7 < d903d99ffd22b0180bd745a43f221c21bcdd8d7caffected
LinuxLinux4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7 < 445204550f894ca325ac80a21e3df177ad073798affected
LinuxLinux4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7 < 4379610c79bd88ddbea10e7f6c21e16d4b338c6baffected
LinuxLinux6.17affected
LinuxLinux0 < 6.17unaffected
LinuxLinux6.18.50 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References