Description
In the Linux kernel, the following vulnerability has been resolved:

drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE

In nouveau_uvmm_bind_job_submit()'s OP_UNMAP_SPARSE arm, op->reg is set
from nouveau_uvma_region_find(), which only looks the region up and takes
no reference; a region's sole reference is its membership in
uvmm->region_mt. Two failure paths leave op->reg set: the -ENOENT check
when the region is busy, and the drm_gpuvm_sm_unmap_ops_create() failure.
The sibling nouveau_uvmm_sm_unmap_prepare() failure just below clears
op->reg; these two do not.

unwind_continue steps back one op, so the failing op is skipped by the
unwind loop and its op->reg stays set. nouveau_uvmm_bind_job_cleanup()
then enters its if (op->reg) branch and calls nouveau_uvma_region_remove()
and nouveau_uvma_region_put() on it, dropping the tree's sole reference
and freeing a region this job never created. The comment above the
cleanup loop documents the broken invariant: op->reg must be NULL on
submit failure.

This frees a live region on an unrelated failure, reachable single-job
when drm_gpuvm_sm_unmap_ops_create() returns -ENOMEM; if another job owns
the same region, its cleanup then removes and puts the freed region, a
use-after-free. Clear op->reg on both failure paths.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free in GPU driver
Action: Patch Immediately
AI Analysis

Impact

The patch addresses a flaw in the Linux nouveau GPU driver where a region object was freed prematurely during a failed unmap operation. This premature free removes the region’s only reference, causing a use‑after‑free when the cleanup routine later attempts to drop the already‑freed object. The resulting memory corruption can lead to data corruption or, in the worst case, arbitrary code execution with kernel privileges. The weakness is a classic use‑after‑free scenario, which in kernel context can elevate an attacker’s capabilities or crash the system.

Affected Systems

The vulnerability affects the Linux kernel’s nouveau component, a generic Linux distribution feature that supports NVIDIA GPUs. No specific kernel release numbers are provided in the data, so any kernel that contains the affected nouveau driver code before the patch is potentially impacted. Deployments that enable the nouveau driver or use GPUs with the nouveau_uvmm feature should review their kernel versions for the presence of the fix.

Risk and Exploitability

The CVSS score of 7.8 reflects a high severity for a kernel bug, yet the EPSS score of less than 1% suggests exploitation attempts are currently rare or not publicly observed. The vulnerability is not listed in the CISA KEV catalog and there is no evidence of a publicly available exploit. The attack requires local kernel access or the ability to trigger GPU driver operations that lead to the failure path, implying that the primary vector is local. Given the kernel context, a successful exploit could compromise the entire system, though the low EPSS indicates that in practice the risk is moderate toward high, pending a local privileged attacker.

Generated by OpenCVE AI on September 18, 2026 at 10:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the nouveau_uvmm fix.
  • If an immediate kernel upgrade is not feasible, cherry‑pick the commit that applies the patch into the current kernel source tree, rebuild, and install the patched kernel.
  • If kernel upgrades or patching are not possible or if the nouveau driver is not required, disable the nouveau module or switch to an alternative GPU driver such as the proprietary NVIDIA driver or Intel’s driver.

Generated by OpenCVE AI on September 18, 2026 at 10:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE In nouveau_uvmm_bind_job_submit()'s OP_UNMAP_SPARSE arm, op->reg is set from nouveau_uvma_region_find(), which only looks the region up and takes no reference; a region's sole reference is its membership in uvmm->region_mt. Two failure paths leave op->reg set: the -ENOENT check when the region is busy, and the drm_gpuvm_sm_unmap_ops_create() failure. The sibling nouveau_uvmm_sm_unmap_prepare() failure just below clears op->reg; these two do not. unwind_continue steps back one op, so the failing op is skipped by the unwind loop and its op->reg stays set. nouveau_uvmm_bind_job_cleanup() then enters its if (op->reg) branch and calls nouveau_uvma_region_remove() and nouveau_uvma_region_put() on it, dropping the tree's sole reference and freeing a region this job never created. The comment above the cleanup loop documents the broken invariant: op->reg must be NULL on submit failure. This frees a live region on an unrelated failure, reachable single-job when drm_gpuvm_sm_unmap_ops_create() returns -ENOMEM; if another job owns the same region, its cleanup then removes and puts the freed region, a use-after-free. Clear op->reg on both failure paths.
Title drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:38:47.092Z

Reserved: 2026-09-11T19:38:34.767Z

Link: CVE-2026-89801

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:44.997

Modified: 2026-09-16T15:18:09.867

Link: CVE-2026-89801

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T10:15:06Z

Weaknesses