SB20260918247 - Out-of-bounds read in Linux kernel arm arm-smmu-v3 driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-90425)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform an out-of-bounds read.
The vulnerability exists due to an out-of-bounds read in tegra241_vintf_init_vsid() when mapping a guest vSID for a device without stream IDs. A local user can request a guest vSID mapping for such a device to perform an out-of-bounds read.
For devices with multiple stream IDs, only the first stream ID is mapped, preventing guest vSID invalidations from reaching the other ATC and IOTLB entries.
Remediation
Install update from vendor's website.