Impact
A NULL dereference in the Nouveau kernel driver can cause the kernel to crash when a previously processed sparse map operation is later reversed during an error cleanup. This results in a denial of service on affected systems, but does not provide direct remote code execution or privilege escalation.
Affected Systems
All Linux kernel installations that include the Nouveau driver prior to the recent fix, especially those where the kernel can be bound via a render‑node file descriptor.
Risk and Exploitability
The EPSS score of less than 1% and the lack of listing in CISA KEV indicate a low probability of widespread exploitation, but the vulnerability can be triggered by any user with access to a render‑node FD. The attack vector is local or potentially authenticated, and exploitation requires the affected kernel to perform a job bind that subsequently fails.
OpenCVE Enrichment
Debian DLA
Debian DSA