CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's handling of the virtual Stream ID (vSID) in the iommu/tegra241-cmdqv component, allowing a guest-controlled vSID to improperly alias the wrong Stream ID due to insufficient bounds checking. This could lead to unauthorized access or manipulation of memory by a virtual machine monitor (VMM). Organizations utilizing Linux systems with virtualization capabilities, particularly those using the affected hardware, should prioritize addressing this vulnerability to mitigate potential security risks.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field tegra241_vintf_init_vsid() programs the guest-provided vSID into SID_MATCH, whose VIRT_SID field spans bits [20:1] with bit 0 as the match-enable flag. The HW therefore matches only a 20-bit Stream ID. The bound check rejects only virt_sid > UINT_MAX, which admits a value far wider than the field. The write "virt_sid << 1 | 0x1" then drops every bit above 20: a virt_sid of 0x80000000 lands as SID_MATCH = 0x1, a valid match on vSID 0, so the entry aliases the wrong Stream ID. Because vdev->virt_id is guest-controlled, a VMM can trigger it. Validate virt_sid against the field width with FIELD_MAX(), and program the register with FIELD_PREP() so the value and the field stay consistent.