Answer in brief
CVE-2026-89450 records a Unknown severity vulnerability in iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7 <d903d99ffd22b0180bd745a43f221c21bcdd8d7c || >=4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7 <445204550f894ca325ac80a21e3df177ad073798 || >=4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7 <4379610c79bd88ddbea10e7f6c21e16d4b338c6b | d903d99ffd22b0180bd745a43f221c21bcdd8d7c, 445204550f894ca325ac80a21e3df177ad073798, 4379610c79bd88ddbea10e7f6c21e16d4b338c6b |
| Linux/Linuxgeneric | 6.17 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field tegra241_vintf_init_vsid() programs the guest-provided vSID into SID_MATCH, whose VIRT_SID field spans bits [20:1] with bit 0 as the match-enable flag. The HW therefore matches only a 20-bit Stream ID. The bound check rejects only virt_sid > UINT_MAX, which admits a value far wider than the field. The write "virt_sid << 1 | 0x1" then drops every bit above 20: a virt_sid of 0x80000000 lands as SID_MATCH = 0x1, a valid match on vSID 0, so the entry aliases the wrong Stream ID. Because vdev->virt_id is guest-controlled, a VMM can trigger it. Validate virt_sid against the field width with FIELD_MAX(), and program the register with FIELD_PREP() so the value and the field stay consistent.
Quoted source text, attributed separately from HOL analysis.