Description
In the Linux kernel, the following vulnerability has been resolved:

drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op

Each bind_job_op is zeroed by kzalloc_obj() in bind_job_op_from_uop(),
and the OP_MAP_SPARSE case in nouveau_uvmm_bind_job_submit() only creates
a region, so op->ops stays NULL for a successfully processed sparse map.

If a later op in the same job fails, the reverse unwind loop revisits that
op and calls drm_gpuva_ops_free(&uvmm->base, op->ops) unconditionally.
drm_gpuva_ops_free() dereferences its argument right away
(list_for_each_entry_safe on &ops->list), so a NULL op->ops oopses. The
path is reachable by any render-node fd holder, since NOUVEAU_VM_BIND is
DRM_RENDER_ALLOW.

Guard the free with IS_ERR_OR_NULL(), as nouveau_uvmm_bind_job_cleanup()
already does for the identical free.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

A NULL dereference in the Nouveau kernel driver can cause the kernel to crash when a previously processed sparse map operation is later reversed during an error cleanup. This results in a denial of service on affected systems, but does not provide direct remote code execution or privilege escalation.

Affected Systems

All Linux kernel installations that include the Nouveau driver prior to the recent fix, especially those where the kernel can be bound via a render‑node file descriptor.

Risk and Exploitability

The EPSS score of less than 1% and the lack of listing in CISA KEV indicate a low probability of widespread exploitation, but the vulnerability can be triggered by any user with access to a render‑node FD. The attack vector is local or potentially authenticated, and exploitation requires the affected kernel to perform a job bind that subsequently fails.

Generated by OpenCVE AI on September 18, 2026 at 10:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel update that includes the nouveau_uvmm_bind_job_cleanup change.
  • Limit access to render‑node device files by setting appropriate permissions or using udev rules to restrict use to trusted users.
  • If GPU acceleration is not needed, disable the Nouveau driver or rendering nodes to eliminate the attack surface.

Generated by OpenCVE AI on September 18, 2026 at 10:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op Each bind_job_op is zeroed by kzalloc_obj() in bind_job_op_from_uop(), and the OP_MAP_SPARSE case in nouveau_uvmm_bind_job_submit() only creates a region, so op->ops stays NULL for a successfully processed sparse map. If a later op in the same job fails, the reverse unwind loop revisits that op and calls drm_gpuva_ops_free(&uvmm->base, op->ops) unconditionally. drm_gpuva_ops_free() dereferences its argument right away (list_for_each_entry_safe on &ops->list), so a NULL op->ops oopses. The path is reachable by any render-node fd holder, since NOUVEAU_VM_BIND is DRM_RENDER_ALLOW. Guard the free with IS_ERR_OR_NULL(), as nouveau_uvmm_bind_job_cleanup() already does for the identical free.
Title drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:30:35.738Z

Reserved: 2026-09-11T19:38:34.767Z

Link: CVE-2026-89802

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:45.113

Modified: 2026-09-16T11:16:45.113

Link: CVE-2026-89802

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T10:15:06Z

Weaknesses