CVE-2026-90427

Summary

In the Linux kernel, the following vulnerability has been resolved:

iommu/tegra241-cmdqv: Don't fall back to a freed smmu after devm_krealloc()

__tegra241_cmdqv_probe() uses devm_krealloc() to grow @smmu into the larger tegra241_cmdqv, which frees the original @smmu once it relocates. A failure after that returned NULL, and the caller then dereferenced the freed @smmu on its fallback path.

Return an int and take @smmu by reference instead, then update *smmu to the reallocated pointer after devm_krealloc() succeeds, so the caller and its fallback path both use the live @smmu rather than the freed original.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux918eb5c856f6ce4cf93b4b38e4b5e156905c5943 < 86197679b293f0601c3331d545f99a70a7780aa9affected
LinuxLinux918eb5c856f6ce4cf93b4b38e4b5e156905c5943 < d4d05f55e9da646ec03adfa77260eb46f4163749affected
LinuxLinux6.12affected
LinuxLinux0 < 6.12unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References