๐Ÿ” CVE Alert

CVE-2026-90427

UNKNOWN 0.0

iommu/tegra241-cmdqv: Don't fall back to a freed smmu after devm_krealloc()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Don't fall back to a freed smmu after devm_krealloc() __tegra241_cmdqv_probe() uses devm_krealloc() to grow @smmu into the larger tegra241_cmdqv, which frees the original @smmu once it relocates. A failure after that returned NULL, and the caller then dereferenced the freed @smmu on its fallback path. Return an int and take @smmu by reference instead, then update *smmu to the reallocated pointer after devm_krealloc() succeeds, so the caller and its fallback path both use the live @smmu rather than the freed original.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
918eb5c856f6ce4cf93b4b38e4b5e156905c5943 < 86197679b293f0601c3331d545f99a70a7780aa9 918eb5c856f6ce4cf93b4b38e4b5e156905c5943 < d4d05f55e9da646ec03adfa77260eb46f4163749
Linux / Linux
6.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/86197679b293f0601c3331d545f99a70a7780aa9 git.kernel.org: https://git.kernel.org/stable/c/d4d05f55e9da646ec03adfa77260eb46f4163749