CVE-2026-80818: iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown
In the Linux kernel, the following vulnerability has been resolved:
iommu/tegra241-cmdqv: Fix CMDSYNC use-after-free on teardown
armsmmuimplremove() is registered as a devres action in armsmmuimplprobe(), before armsmmuinitqueues() allocates smmu->cmdq.q.base. On a devres unwind, whether a failed probe or an unbind, the queue is freed first and armsmmuimplremove() then runs tegra241cmdqvremovevintf(), whose VINTF deinit issues a CMDSYNC on the freed memory.
Observed during testing with a QEMU hack that makes the VCMDQ fail to enable, so the impl reset fails and probe aborts into the devres unwind:
platform NVDA200C:00: tegra241cmdqv: VINTF0: VCMDQ0/LVCMDQ0: failed to enable, STATUS=0x00000000 platform NVDA200C:00: tegra241cmdqv: VINTF0: VCMDQ0/LVCMDQ0: GERRORN=0x0, GERROR=0x4, CONS=0x0 platform NVDA200C:00: tegra241cmdqv: VINTF0: VCMDQ0/LVCMDQ0: uncleared error detected, resetting arm-smmu-v3 arm-smmu-v3.0.auto: failed to reset impl arm-smmu-v3 arm-smmu-v3.0.auto: probe with driver arm-smmu-v3 failed with error -110 Unable to handle kernel paging request at virtual address ffff8000891e0098 ... Internal error: Oops: 0000000096000047 [#1] SMP ... Call trace: armsmmucmdqissuecmdlist+0x320/0x6fc (P) tegra241vcmdqhwdeinit+0x98/0x168 tegra241vintfhwdeinit+0x5c/0x1b0 tegra241cmdqvremovevintf+0x34/0xec tegra241cmdqvremove+0x40/0x9c armsmmuimplremove+0x20/0x30 devmactionrelease+0x14/0x20 devresreleaseall+0xa8/0x110 deviceunbindcleanup+0x18/0x84 reallyprobe+0x1f0/0x29c
Drop the VINTF deinit from tegra241cmdqvremovevintf() so the unwind no longer touches the freed queue. Quiesce the VINTFs earlier instead. Add a devicedisable() impl op and run it from armsmmudisableaction() while the CMDQ is still up. That handles a live unbind. A failed reset is already handled because tegra241vintfhwinit() deinits the VINTF on its own error path. tegra241cmdqvremovevintf() is also used by the iommufd viommu destroy path, so quiesce there too.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Systems using the Linux kernel arm-smmu-v3 driver with the Tegra241 CMDQ virtual interface are affected during driver probe failure or device unbind teardown. The reported failure path involves a VCMDQ that fails to enable.
What event triggers the use-after-free?
A devres unwind frees the SMMU command queue before arm_smmu_impl_remove() runs. The Tegra241 VINTF deinitialization then issues CMD_SYNC using the already-freed command-queue memory.
How might an affected system present?
A failed arm-smmu-v3 probe or unbind can lead to a kernel paging request and Oops during teardown. The example logs include a VCMDQ enable failure, an implementation reset failure, and probe failure with error -110.