{"id":"CVE-2026-90426","title":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs\n\ntegra241_cmdqv_remove() tears each VINTF down first, then calls free_irq().\nTearing a VINTF down fr…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs\n\ntegra241_cmdqv_remove() tears each VINTF down first, then calls free_irq().\nTearing a VINTF down fr…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 918eb5c856f6ce4cf93b4b38e4b5e156905c5943 < 076a4f5b1fc2016b973a12bc2ebb9b730e5e1e48","Linux >= 918eb5c856f6ce4cf93b4b38e4b5e156905c5943 < 735698e81f798b4c02dcb6291ffbdd1b962c8c66","Linux >= 918eb5c856f6ce4cf93b4b38e4b5e156905c5943 < 421f5ab135cd4a1353891e5bf2602cfc3c01afc7","Linux >= 918eb5c856f6ce4cf93b4b38e4b5e156905c5943 < 61f0d437988e5730b04442f6a7d30a9907339f2a","Linux 6.12"],"published":"2026-09-17","updated":"2026-09-17","sourceUpdated":"2026-09-17T17:17:47.353","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90426","references":[{"url":"https://git.kernel.org/stable/c/076a4f5b1fc2016b973a12bc2ebb9b730e5e1e48","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/421f5ab135cd4a1353891e5bf2602cfc3c01afc7","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/61f0d437988e5730b04442f6a7d30a9907339f2a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/735698e81f798b4c02dcb6291ffbdd1b962c8c66","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-17T16:21:47.793Z","epss":0.002,"epssPercentile":0.10121,"slug":"CVE-2026-90426","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\niommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs\n\ntegra241_cmdqv_remove() tears each VINTF down first, then calls free_irq().\nTearing a VINTF down frees vintf0 and clears cmdqv->vintfs[0]. An error in\nthat window makes tegra241_cmdqv_isr() read the stale slot and hand it to\ntegra241_vintf0_handle_error(), which dereferences a NULL or freed pointer.\n\nFree the IRQ before tearing the VINTFs down. free_irq() waits for in-flight\nhandlers to finish and blocks new ones, so no ISR can observe a VINTF as it\nis torn down.\n\nNote: a user-owned VINTF (viommu) could outlive this teardown, which unmaps\ncmdqv->base and frees cmdqv->vintfs, so a later viommu close then touches\nfreed memory. This is neither introduced nor fixed here: a physical IOMMU\nis not a pluggable device, so iommufd by design holds no reference on the\none behind a viommu, and this teardown is not expected while that viommu is\nstill alive.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}