{"id":"CVE-2026-89450","title":"kernel: iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field (CVE-2026-89450)","summary":"A flaw was found in the Linux kernel's iommu/tegra241-cmdqv module. A Virtual Machine Manager (VMM) can exploit this vulnerability by providing a virtual Stream ID (vSID) that exceeds the intended 20-bit width of the SID_MATCH field. This …","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-681","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T19:14:05+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89450.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89450.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89450"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532062"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89450"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89450"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89450.mbox"},{"url":"https://git.kernel.org/stable/c/4379610c79bd88ddbea10e7f6c21e16d4b338c6b"},{"url":"https://git.kernel.org/stable/c/445204550f894ca325ac80a21e3df177ad073798"},{"url":"https://git.kernel.org/stable/c/d903d99ffd22b0180bd745a43f221c21bcdd8d7c"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00127,"epssPercentile":0.02717,"scores":{"vendor":7,"cna":8.8},"ingestedAt":"2026-09-14T15:23:07.475Z","slug":"CVE-2026-89450","body":"## Overview\n\nA flaw was found in the Linux kernel's iommu/tegra241-cmdqv module. A Virtual Machine Manager (VMM) can exploit this vulnerability by providing a virtual Stream ID (vSID) that exceeds the intended 20-bit width of the SID_MATCH field. This improper input validation causes the system to incorrectly process the vSID, leading to the aliasing of an unintended Stream ID. This could result in unexpected behavior or security bypasses within the IOMMU.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89450.json)\n\n**kernel: iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field** — rated Important by Red Hat. Released 2026-09-11, updated 2026-09-14.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nAffected","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":203031,"id":"CVE-2026-89450","ts":1789403733426,"field":"cvss","old":"8.8","new":"7"},{"seq":198060,"id":"CVE-2026-89450","ts":1789384321609,"field":"cvss","old":"7","new":"8.8"},{"seq":183795,"id":"CVE-2026-89450","ts":1789356677425,"field":"cvss","old":"8.8","new":"7"},{"seq":153232,"id":"CVE-2026-89450","ts":1789285349653,"field":"cvss","old":null,"new":"8.8"},{"seq":153231,"id":"CVE-2026-89450","ts":1789285349653,"field":"severity","old":"none","new":"high"},{"seq":109602,"id":"CVE-2026-89450","ts":1789183732580,"field":"cvss","old":null,"new":"7"},{"seq":109601,"id":"CVE-2026-89450","ts":1789183732580,"field":"severity","old":"none","new":"high"}]}