SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-89450

HIGH · CVSS 8.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of the virtual Stream ID (vSID) in the iommu/tegra241-cmdqv component, allowing a guest-controlled vSID to improperly alias the wrong Stream ID due to insufficient bounds checking. This could lead to unauthorized access or manipulation of memory by a virtual machine monitor (VMM). Organizations utilizing Linux systems with virtualization capabilities, particularly those using the affected hardware, should prioritize addressing this vulnerability to mitigate potential security risks.

CVE
CVE-2026-89450
Severity
HIGH
CVSS
8.8
EPSS
0.13%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field tegra241_vintf_init_vsid() programs the guest-provided vSID into SID_MATCH, whose VIRT_SID field spans bits [20:1] with bit 0 as the match-enable flag. The HW therefore matches only a 20-bit Stream ID. The bound check rejects only virt_sid > UINT_MAX, which admits a value far wider than the field. The write "virt_sid << 1 | 0x1" then drops every bit above 20: a virt_sid of 0x80000000 lands as SID_MATCH = 0x1, a valid match on vSID 0, so the entry aliases the wrong Stream ID. Because vdev->virt_id is guest-controlled, a VMM can trigger it. Validate virt_sid against the field width with FIELD_MAX(), and program the register with FIELD_PREP() so the value and the field stay consistent.