{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80818","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.795Z","datePublished":"2026-09-04T15:13:39.273Z","dateUpdated":"2026-09-04T15:13:39.273Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-04T15:13:39.273Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown\n\narm_smmu_impl_remove() is registered as a devres action in\narm_smmu_impl_probe(), before arm_smmu_init_queues() allocates\nsmmu->cmdq.q.base. On a devres unwind, whether a failed probe or an\nunbind, the queue is freed first and arm_smmu_impl_remove() then runs\ntegra241_cmdqv_remove_vintf(), whose VINTF deinit issues a CMD_SYNC on\nthe freed memory.\n\nObserved during testing with a QEMU hack that makes the VCMDQ fail to\nenable, so the impl reset fails and probe aborts into the devres unwind:\n\n platform NVDA200C:00: tegra241_cmdqv: VINTF0: VCMDQ0/LVCMDQ0: failed to enable, STATUS=0x00000000\n platform NVDA200C:00: tegra241_cmdqv: VINTF0: VCMDQ0/LVCMDQ0: GERRORN=0x0, GERROR=0x4, CONS=0x0\n platform NVDA200C:00: tegra241_cmdqv: VINTF0: VCMDQ0/LVCMDQ0: uncleared error detected, resetting\n arm-smmu-v3 arm-smmu-v3.0.auto: failed to reset impl\n arm-smmu-v3 arm-smmu-v3.0.auto: probe with driver arm-smmu-v3 failed with error -110\n Unable to handle kernel paging request at virtual address ffff8000891e0098\n ...\n Internal error: Oops: 0000000096000047 [#1] SMP\n ...\n Call trace:\n  arm_smmu_cmdq_issue_cmdlist+0x320/0x6fc (P)\n  tegra241_vcmdq_hw_deinit+0x98/0x168\n  tegra241_vintf_hw_deinit+0x5c/0x1b0\n  tegra241_cmdqv_remove_vintf+0x34/0xec\n  tegra241_cmdqv_remove+0x40/0x9c\n  arm_smmu_impl_remove+0x20/0x30\n  devm_action_release+0x14/0x20\n  devres_release_all+0xa8/0x110\n  device_unbind_cleanup+0x18/0x84\n  really_probe+0x1f0/0x29c\n\nDrop the VINTF deinit from tegra241_cmdqv_remove_vintf() so the unwind no\nlonger touches the freed queue. Quiesce the VINTFs earlier instead. Add a\ndevice_disable() impl op and run it from arm_smmu_disable_action() while\nthe CMDQ is still up. That handles a live unbind. A failed reset is already\nhandled because tegra241_vintf_hw_init() deinits the VINTF on its own error\npath. tegra241_cmdqv_remove_vintf() is also used by the iommufd viommu\ndestroy path, so quiesce there too."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c","drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.h","drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c"],"versions":[{"version":"4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7","lessThan":"d2ab08437e913d9e4dda4dfd0d327446ec8717fc","status":"affected","versionType":"git"},{"version":"4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7","lessThan":"a94309bb99eaf0c6a2ace4927864486d19458eb5","status":"affected","versionType":"git"},{"version":"4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7","lessThan":"5994617e09ee6016c1b094f29d9c85cac944b477","status":"affected","versionType":"git"},{"version":"4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7","lessThan":"9ff145a25c5c8a26b06ef7cf558fb536b18bba6d","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c","drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.h","drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c"],"versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","status":"unaffected","versionType":"semver"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"6.18.47"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"7.1.11"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"7.2.1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/d2ab08437e913d9e4dda4dfd0d327446ec8717fc"},{"url":"https://git.kernel.org/stable/c/a94309bb99eaf0c6a2ace4927864486d19458eb5"},{"url":"https://git.kernel.org/stable/c/5994617e09ee6016c1b094f29d9c85cac944b477"},{"url":"https://git.kernel.org/stable/c/9ff145a25c5c8a26b06ef7cf558fb536b18bba6d"}],"title":"iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown","x_generator":{"engine":"bippy-1.2.0"}}}}