CVE-2026-90425

8.8

Linux · Kernel

A memory management flaw in the Linux kernel tegra241-cmdqv driver allows out of bounds memory access due to improper validation of Stream IDs for vSIDs.

Executive summary

A high severity out of bounds memory access vulnerability in the Linux kernel tegra241-cmdqv driver poses a significant risk of system compromise and instability.

Vulnerability

The tegra241_vintf_init_vsid function fails to correctly validate the number of physical Stream IDs mapped to a guest vSID. An attacker with local low-level privileges can trigger an out of bounds read or improper memory mapping, potentially leading to privilege escalation or system crashes.

Business impact

Successful exploitation of this flaw allows an attacker to achieve high impact on confidentiality, integrity, and availability. Given the CVSS score of 8.8, this vulnerability represents a critical risk to systems utilizing Tegra-based virtualization, as it could permit a guest to bypass security boundaries or corrupt host kernel memory.

Remediation

Immediate Action: Update the Linux kernel to version 6.18.52, 7.2.6, or a later stable release where this issue has been resolved.

Proactive Monitoring: Monitor system logs for kernel panic events or unexpected hardware driver errors related to IOMMU or Tegra-based components.

Compensating Controls: Restrict access to virtualized environments and ensure that untrusted users cannot execute arbitrary code within guest instances that interact with the vulnerable tegra241-cmdqv driver.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a serious risk to the stability and security of the Linux kernel on affected hardware platforms. System administrators should prioritize testing and deploying the provided kernel patches to all production environments running the affected versions to prevent potential exploitation of the memory management flaw.

More Linux CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. Analyst report written
  4. Published in the daily brief high section

Sources