---
id: CVE-2026-90426
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs

  tegra241_cmdqv_remove() tears each VINTF down first, then calls free_irq().
  Tearing a VINTF down fr…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs

  tegra241_cmdqv_remove() tears each VINTF down first, then calls free_irq().
  Tearing a VINTF down fr…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 918eb5c856f6ce4cf93b4b38e4b5e156905c5943 <
    076a4f5b1fc2016b973a12bc2ebb9b730e5e1e48
  - >-
    Linux >= 918eb5c856f6ce4cf93b4b38e4b5e156905c5943 <
    735698e81f798b4c02dcb6291ffbdd1b962c8c66
  - >-
    Linux >= 918eb5c856f6ce4cf93b4b38e4b5e156905c5943 <
    421f5ab135cd4a1353891e5bf2602cfc3c01afc7
  - >-
    Linux >= 918eb5c856f6ce4cf93b4b38e4b5e156905c5943 <
    61f0d437988e5730b04442f6a7d30a9907339f2a
  - Linux 6.12
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:17:47.353'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90426'
references:
  - url: 'https://git.kernel.org/stable/c/076a4f5b1fc2016b973a12bc2ebb9b730e5e1e48'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/421f5ab135cd4a1353891e5bf2602cfc3c01afc7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/61f0d437988e5730b04442f6a7d30a9907339f2a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/735698e81f798b4c02dcb6291ffbdd1b962c8c66'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.793Z'
epss: 0.00209
epssPercentile: 0.09803
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs

tegra241_cmdqv_remove() tears each VINTF down first, then calls free_irq().
Tearing a VINTF down frees vintf0 and clears cmdqv->vintfs[0]. An error in
that window makes tegra241_cmdqv_isr() read the stale slot and hand it to
tegra241_vintf0_handle_error(), which dereferences a NULL or freed pointer.

Free the IRQ before tearing the VINTFs down. free_irq() waits for in-flight
handlers to finish and blocks new ones, so no ISR can observe a VINTF as it
is torn down.

Note: a user-owned VINTF (viommu) could outlive this teardown, which unmaps
cmdqv->base and frees cmdqv->vintfs, so a later viommu close then touches
freed memory. This is neither introduced nor fixed here: a physical IOMMU
is not a pluggable device, so iommufd by design holds no reference on the
one behind a viommu, and this teardown is not expected while that viommu is
still alive.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
