CVE-2026-89450
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field
tegra241_vintf_init_vsid() programs the guest-provided vSID into SID_MATCH, whose VIRT_SID field spans bits [20:1] with bit 0 as the match-enable flag. The HW therefore matches only a 20-bit Stream ID.
The bound check rejects only virt_sid > UINT_MAX, which admits a value far wider than the field. The write "virt_sid << 1 | 0x1" then drops every bit above 20: a virt_sid of 0x80000000 lands as SID_MATCH = 0x1, a valid match on vSID 0, so the entry aliases the wrong Stream ID. Because vdev->virt_id is guest-controlled, a VMM can trigger it.
Validate virt_sid against the field width with FIELD_MAX(), and program the register with FIELD_PREP() so the value and the field stay consistent.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7 < d903d99ffd22b0180bd745a43f221c21bcdd8d7c | affected |
| Linux | Linux | 4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7 < 445204550f894ca325ac80a21e3df177ad073798 | affected |
| Linux | Linux | 4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7 < 4379610c79bd88ddbea10e7f6c21e16d4b338c6b | affected |
| Linux | Linux | 6.17 | affected |
| Linux | Linux | 0 < 6.17 | unaffected |
| Linux | Linux | 6.18.50 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.4 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/d903d99ffd22b0180bd745a43f221c21bcdd8d7c
- https://git.kernel.org/stable/c/445204550f894ca325ac80a21e3df177ad073798
- https://git.kernel.org/stable/c/4379610c79bd88ddbea10e7f6c21e16d4b338c6b
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.