CVE-2026-53310 PUBLISHED

soc/tegra: cbb: Fix cross-fabric target timeout lookup

Assigner: Linux
Reserved: 09.06.2026 Published: 26.06.2026 Updated: 26.06.2026

In the Linux kernel, the following vulnerability has been resolved:

soc/tegra: cbb: Fix cross-fabric target timeout lookup

When a fabric receives an error interrupt, the error may have occurred on a different fabric. The target timeout lookup was using the wrong base address (cbb->regs) with offsets from a different fabric's target map, causing a kernel page fault.

Unable to handle kernel paging request at virtual address ffff80000954cc00 pc : tegra234_cbb_get_tmo_slv+0xc/0x28 Call trace: tegra234_cbb_get_tmo_slv+0xc/0x28 print_err_notifier+0x6c0/0x7d0 tegra234_cbb_isr+0xe4/0x1b4

Add tegra234_cbb_get_fabric() to look up the correct fabric device using fab_id, and use its base address for accessing target timeout registers.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 25de5c8fe0801361182b41c42f086bd089feda14 to c892d0d4fe5ec05d3fdfb1616c3c0e3c12ef5abc (excl.)
  • affected from 25de5c8fe0801361182b41c42f086bd089feda14 to 8445d69a5cabd8d6cb2bf0f8b798be205f53afa2 (excl.)
  • affected from 25de5c8fe0801361182b41c42f086bd089feda14 to a5f51b04cbb3ae0f9cb2c4488952b775ebb0ccbf (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.17 is affected
  • unaffected from 0 to 6.17 (excl.)
  • unaffected from 6.18.33 to 6.18.* (incl.)
  • unaffected from 7.0.10 to 7.0.* (incl.)
  • unaffected from 7.1 to * (incl.)

References