Description
In the Linux kernel, the following vulnerability has been resolved:

nouveau/gem: reserve the bo in the info ioctl around the vma lookup

In the non-uvmm path, there could be a race between the info lookup
finding the vma, and the gem close path closing the vma leading
to a use-after-free.

Spotted with the help of Opus 4.6.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel, a race condition exists between the nouveau graphics driver ioctl that looks up buffer object information and the gem close path that removes virtual memory areas. When the lookup occurs while the area is being closed, the driver can attempt to access freed memory, resulting in a use-after-free bug.

Affected Systems

All Linux kernel versions that include the unpatched nouveau driver code are vulnerable. The CNA vendor list indicates that this is a Linux kernel issue, affecting all distributions that ship an unmodified kernel with the legacy nouveau driver. No specific version information is provided, so any kernel prior to the application of the posted patch is at risk.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity. The EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting that exploitation is unlikely at present. Exploitation would require an attacker to coordinate a timing race between the info ioctl and a gem‑close operation, which typically requires local privileged access or the ability to invoke the vulnerable ioctl. No further impact such as privilege escalation is stated in the description.

Generated by OpenCVE AI on September 15, 2026 at 21:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that removes the race condition in the nouveau driver.
  • If the patch is not yet available, disable or blacklist the nouveau driver to prevent the race condition.
  • Keep the kernel updated and apply future vendor advisories for nouveau and GPU components.

Generated by OpenCVE AI on September 15, 2026 at 21:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-367
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nouveau/gem: reserve the bo in the info ioctl around the vma lookup In the non-uvmm path, there could be a race between the info lookup finding the vma, and the gem close path closing the vma leading to a use-after-free. Spotted with the help of Opus 4.6.
Title nouveau/gem: reserve the bo in the info ioctl around the vma lookup
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:00:55.789Z

Reserved: 2026-09-11T19:38:34.723Z

Link: CVE-2026-89553

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:38.887

Modified: 2026-09-14T13:19:10.320

Link: CVE-2026-89553

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:26Z

Links: CVE-2026-89553 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:00:17Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition