SB20260918247 - Out-of-bounds read in Linux kernel arm arm-smmu-v3 driver



SB20260918247 - Out-of-bounds read in Linux kernel arm arm-smmu-v3 driver

Published: September 18, 2026

Security Bulletin ID SB20260918247
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Out-of-bounds read (CVE-ID: CVE-2026-90425)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform an out-of-bounds read.

The vulnerability exists due to an out-of-bounds read in tegra241_vintf_init_vsid() when mapping a guest vSID for a device without stream IDs. A local user can request a guest vSID mapping for such a device to perform an out-of-bounds read.

For devices with multiple stream IDs, only the first stream ID is mapped, preventing guest vSID invalidations from reaching the other ATC and IOTLB entries.


Remediation

Install update from vendor's website.