Answer in brief
CVE-2026-90426 records a Unknown severity vulnerability in iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=918eb5c856f6ce4cf93b4b38e4b5e156905c5943 <076a4f5b1fc2016b973a12bc2ebb9b730e5e1e48 || >=918eb5c856f6ce4cf93b4b38e4b5e156905c5943 <735698e81f798b4c02dcb6291ffbdd1b962c8c66 || >=918eb5c856f6ce4cf93b4b38e4b5e156905c5943 <421f5ab135cd4a1353891e5bf2602cfc3c01afc7 || >=918eb5c856f6ce4cf93b4b38e4b5e156905c5943 <61f0d437988e5730b04442f6a7d30a9907339f2a | 076a4f5b1fc2016b973a12bc2ebb9b730e5e1e48, 735698e81f798b4c02dcb6291ffbdd1b962c8c66, 421f5ab135cd4a1353891e5bf2602cfc3c01afc7, 61f0d437988e5730b04442f6a7d30a9907339f2a |
| Linux/Linuxgeneric | 6.12 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs tegra241_cmdqv_remove() tears each VINTF down first, then calls free_irq(). Tearing a VINTF down frees vintf0 and clears cmdqv->vintfs[0]. An error in that window makes tegra241_cmdqv_isr() read the stale slot and hand it to tegra241_vintf0_handle_error(), which dereferences a NULL or freed pointer. Free the IRQ before tearing the VINTFs down. free_irq() waits for in-flight handlers to finish and blocks new ones, so no ISR can observe a VINTF as it is torn down. Note: a user-owned VINTF (viommu) could outlive this teardown, which unmaps cmdqv->base and frees cmdqv->vintfs, so a later viommu close then touches freed memory. This is neither introduced nor fixed here: a physical IOMMU is not a pluggable device, so iommufd by design holds no reference on the one behind a viommu, and this teardown is not expected while that viommu is still alive.
Quoted source text, attributed separately from HOL analysis.