Description
In the Linux kernel, the following vulnerability has been resolved:

drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE

A successful OP_UNMAP_SPARSE marks its region dirty with
nouveau_uvma_region_dirty() and defers the teardown to
nouveau_uvmm_bind_job_cleanup(); it does not remove the region from
uvmm->region_mt.

If a later op in the job fails, the unwind path never clears reg->dirty
(set in one place, cleared nowhere) and sets op->reg = NULL, so cleanup
skips the teardown. The region is left in the tree with dirty set and its
completion never signalled. Later binds over that range then fail
permanently -- -ENOENT or -EINVAL from the dirty checks, or an unkillable
wait_for_completion() in bind_validate_region() -- for the lifetime of
the uvmm.

Clear reg->dirty when the unwind reverts the sparse unmap, restoring the
region to the state it was found in.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A flaw in the Linux kernel’s Nouveau UVM memory manager causes a region dirty flag to remain set after a failed OP_UNMAP_SPARSE operation. Because the unwind path does not clear reg->dirty, the later cleanup skips tearing down the region, leaving it in the tree and never signaling completion. Subsequent GPU bind operations over that range therefore fail permanently with either -ENOENT or -EINVAL due to the dirty check, or hang in an unkillable wait for completion. An attacker who can cause the OP_UNMAP_SPARSE to fail (for example, by manipulating GPU memory mappings) can trigger this failure path, resulting in a sustained denial of GPU services for the lifetime of the uvmm instance.

Affected Systems

The vulnerability affects the Linux kernel’s DRM/Nouveau user-space virtual memory manager (uvmm), present in all kernel versions that include this driver. No specific affected kernel releases are listed in the CVE data; the issue is present in any kernel where the bug exists until the patch is applied.

Risk and Exploitability

The reported EPSS score is less than 1%, and the vulnerability is not listed in CISA’s KEV catalog. The attack likely requires local exploitation of GPU operations that trigger the problematic unmap sequence; information on the exact attack vector is not provided, so it is inferred that a local privileged attacker could induce the failure by manipulating GPU memory. Given the lack of widespread exploitation evidence, the likelihood of exploitation remains low, but the impact is high if the flaw is leveraged, as it can cause persistent denial of GPU functionality permanently for the affected process. The CVSS score is not published, but the remedial action is to apply the available patch as soon as it is released.

Generated by OpenCVE AI on September 18, 2026 at 10:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel update that includes the fix for the Nouveau UVMM dirty flag bug
  • Reboot the system to load the patched kernel and ensure UVM modules are initialized
  • If GPU workloads are critical, temporarily reduce GPU usage or switch to an alternate graphics driver until the patch is deployed

Generated by OpenCVE AI on September 18, 2026 at 10:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1128
CWE-762

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE A successful OP_UNMAP_SPARSE marks its region dirty with nouveau_uvma_region_dirty() and defers the teardown to nouveau_uvmm_bind_job_cleanup(); it does not remove the region from uvmm->region_mt. If a later op in the job fails, the unwind path never clears reg->dirty (set in one place, cleared nowhere) and sets op->reg = NULL, so cleanup skips the teardown. The region is left in the tree with dirty set and its completion never signalled. Later binds over that range then fail permanently -- -ENOENT or -EINVAL from the dirty checks, or an unkillable wait_for_completion() in bind_validate_region() -- for the lifetime of the uvmm. Clear reg->dirty when the unwind reverts the sparse unmap, restoring the region to the state it was found in.
Title drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:30:33.097Z

Reserved: 2026-09-11T19:38:34.767Z

Link: CVE-2026-89800

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:44.877

Modified: 2026-09-16T11:16:44.877

Link: CVE-2026-89800

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T10:15:06Z

Weaknesses