← All Advisories

CVE-2026-93205

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-93205

Key Details

CVECVE-2026-93205
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

iommu/arm-smmu-v3: Manage teardown with devm

arm_smmu_device_remove() manually frees the IOPF queue, destroys the

vmid_map and disables the device, while the IRQs and queues are devm

managed. devm unwinds only after remove() returns, so the cleanup runs

in the wrong order. The IOPF queue is freed before the event-queue IRQ

whose handler uses it.

Manage all of it with devm so the unwind order is correct. Free the IOPF

queue and vmid_map via devm actions, and disable the device from one

registered after arm_smmu_device_reset().

This is also a prerequisite for fixing a Tegra241 CMDQV CMD_SYNC

use-after-free in the subsequent patch. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-93205
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-93205