Numeric Truncation Error in Linux kernel - CVE-2026-89450
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause stream ID aliasing.
The vulnerability exists due to improper validation of virtual stream ID width in the tegra241-cmdqv virtual interface SID_MATCH register programming when configuring a guest-provided virtual stream ID. A local privileged user can supply a virtual stream ID exceeding the SID_MATCH field width to cause stream ID aliasing.
The hardware matches only a 20-bit stream ID.