CVE-2026-90426

Source
https://cve.org/CVERecord?id=CVE-2026-90426
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90426.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90426
Downstream
Published
2026-09-17T16:09:48Z
Modified
2026-09-19T03:47:26Z
Summary
iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs
Details

In the Linux kernel, the following vulnerability has been resolved:

iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs

tegra241_cmdqv_remove() tears each VINTF down first, then calls free_irq(). Tearing a VINTF down frees vintf0 and clears cmdqv->vintfs[0]. An error in that window makes tegra241_cmdqv_isr() read the stale slot and hand it to tegra241_vintf0_handle_error(), which dereferences a NULL or freed pointer.

Free the IRQ before tearing the VINTFs down. free_irq() waits for in-flight handlers to finish and blocks new ones, so no ISR can observe a VINTF as it is torn down.

Note: a user-owned VINTF (viommu) could outlive this teardown, which unmaps cmdqv->base and frees cmdqv->vintfs, so a later viommu close then touches freed memory. This is neither introduced nor fixed here: a physical IOMMU is not a pluggable device, so iommufd by design holds no reference on the one behind a viommu, and this teardown is not expected while that viommu is still alive.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90426.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
918eb5c856f6ce4cf93b4b38e4b5e156905c5943
Fixed
076a4f5b1fc2016b973a12bc2ebb9b730e5e1e48
Fixed
735698e81f798b4c02dcb6291ffbdd1b962c8c66
Fixed
421f5ab135cd4a1353891e5bf2602cfc3c01afc7
Fixed
61f0d437988e5730b04442f6a7d30a9907339f2a

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90426.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.12.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90426.json"