Impact
The Linux kernel’s nouveau DRM driver unsubscribes from the channel‑kill event after deleting the fence context, allowing the event handler to access memory that has already been freed. If a channel kill occurs during this narrow window the unreleased context is referenced, which can trigger a kernel panic. Such a crash can be leveraged locally to gain elevated privileges or simply cause a denial of service to the system.
Affected Systems
The vulnerability affects any Linux system that uses the Linux kernel with the nouveau graphics driver (the upstream kernel). No specific impacted kernel versions are listed, but all kernels that have not yet integrated the patch are susceptible. Updating to a patched kernel removes the flaw.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score of less than 1% suggests that exploitation, while theoretically possible, is not common or widely seen. The vulnerability is not yet in the CISA KEV catalog. The attack vector appears to be local, requiring a user or process that can trigger a GPU channel kill event. If such an event occurs during channel teardown, the resulting kernel crash can be abused for privilege escalation. In practice, the window is narrow, making successful exploitation difficult.
OpenCVE Enrichment
Debian DLA
Debian DSA