CVE-2026-89450
8.8Linux · Kernel
A boundary validation flaw in the Linux kernel tegra241-cmdqv driver allows a guest-controlled virtual Stream ID to alias an incorrect physical Stream ID, potentially leading to unauthorized access.
Executive summary
A high-severity input validation vulnerability in the Linux kernel tegra241-cmdqv driver could allow a malicious guest to bypass Stream ID protections and achieve elevated system access.
Vulnerability
This is an input validation vulnerability where the tegra241_vintf_init_vsid function fails to properly restrict the virtual Stream ID (vSID) width. An authenticated local attacker, acting as a guest virtual machine monitor, can provide a specially crafted vSID that aliases legitimate Stream IDs, leading to unauthorized memory or device access.
Business impact
The vulnerability carries a CVSS score of 8.8, reflecting its potential for full system compromise. Successful exploitation allows an attacker to bypass IOMMU protections, potentially leading to unauthorized data access, modification, or a complete denial of service for the host system. This represents a significant risk to virtualized environments and multi-tenant cloud infrastructures.
Remediation
Immediate Action: Upgrade the Linux kernel to version 6.18.50, 7.2.4, or later versions where the fix has been implemented.
Proactive Monitoring: Monitor system logs for unusual IOMMU-related errors or unexpected guest-to-host communication patterns that might indicate exploitation attempts.
Compensating Controls: Ensure strict isolation policies for virtual machines and limit the privileges of guest environments where possible to minimize the attack surface.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the severity of this vulnerability and its potential to compromise the isolation of virtualized environments, organizations should prioritize patching the Linux kernel across all affected hosts. Administrators must verify their current kernel versions against the fixed releases and schedule maintenance windows to apply the necessary security updates immediately to eliminate this risk.
More Linux CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.8 (3.1)
- Analyst report written
- Published in the daily brief high section