Impact
A flaw in the Linux kernel’s Nouveau UVM memory manager causes a region dirty flag to remain set after a failed OP_UNMAP_SPARSE operation. Because the unwind path does not clear reg->dirty, the later cleanup skips tearing down the region, leaving it in the tree and never signaling completion. Subsequent GPU bind operations over that range therefore fail permanently with either -ENOENT or -EINVAL due to the dirty check, or hang in an unkillable wait for completion. An attacker who can cause the OP_UNMAP_SPARSE to fail (for example, by manipulating GPU memory mappings) can trigger this failure path, resulting in a sustained denial of GPU services for the lifetime of the uvmm instance.
Affected Systems
The vulnerability affects the Linux kernel’s DRM/Nouveau user-space virtual memory manager (uvmm), present in all kernel versions that include this driver. No specific affected kernel releases are listed in the CVE data; the issue is present in any kernel where the bug exists until the patch is applied.
Risk and Exploitability
The reported EPSS score is less than 1%, and the vulnerability is not listed in CISA’s KEV catalog. The attack likely requires local exploitation of GPU operations that trigger the problematic unmap sequence; information on the exact attack vector is not provided, so it is inferred that a local privileged attacker could induce the failure by manipulating GPU memory. Given the lack of widespread exploitation evidence, the likelihood of exploitation remains low, but the impact is high if the flaw is leveraged, as it can cause persistent denial of GPU functionality permanently for the affected process. The CVSS score is not published, but the remedial action is to apply the available patch as soon as it is released.
OpenCVE Enrichment
Debian DLA
Debian DSA