Impact
In the Linux kernel, a race condition exists between the nouveau graphics driver ioctl that looks up buffer object information and the gem close path that removes virtual memory areas. When the lookup occurs while the area is being closed, the driver can attempt to access freed memory, resulting in a use-after-free bug.
Affected Systems
All Linux kernel versions that include the unpatched nouveau driver code are vulnerable. The CNA vendor list indicates that this is a Linux kernel issue, affecting all distributions that ship an unmodified kernel with the legacy nouveau driver. No specific version information is provided, so any kernel prior to the application of the posted patch is at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting that exploitation is unlikely at present. Exploitation would require an attacker to coordinate a timing race between the info ioctl and a gem‑close operation, which typically requires local privileged access or the ability to invoke the vulnerable ioctl. No further impact such as privilege escalation is stated in the description.
OpenCVE Enrichment
Debian DSA