# CVE-2026-89450

## Summary

- **CVE ID:** CVE-2026-89450
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 13, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field

tegra241_vintf_init_vsid() programs the guest-provided vSID into SID_MATCH,
whose VIRT_SID field spans bits [20:1] with bit 0 as the match-enable flag.
The HW therefore matches only a 20-bit Stream ID.

The bound check rejects only virt_sid > UINT_MAX, which admits a value far
wider than the field. The write "virt_sid << 1 | 0x1" then drops every bit
above 20: a virt_sid of 0x80000000 lands as SID_MATCH = 0x1, a valid match
on vSID 0, so the entry aliases the wrong Stream ID. Because vdev->virt_id
is guest-controlled, a VMM can trigger it.

Validate virt_sid against the field width with FIELD_MAX(), and program the
register with FIELD_PREP() so the value and the field stay consistent.

## Affected Products

- Linux — Linux (4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7)
- Linux — Linux (6.17)
- Linux — Linux (0)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)

## References

- [CNA](https://git.kernel.org/stable/c/d903d99ffd22b0180bd745a43f221c21bcdd8d7c)
- [CNA](https://git.kernel.org/stable/c/445204550f894ca325ac80a21e3df177ad073798)
- [CNA](https://git.kernel.org/stable/c/4379610c79bd88ddbea10e7f6c21e16d4b338c6b)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.13%
- **EPSS Percentile:** 2.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._