Description
In the Linux kernel, the following vulnerability has been resolved:

drm/nouveau: unsubscribe the channel-kill event before the fence context

nouveau_channel_del() tears the fence context down first and only drops
the channel-kill subscription later, in the middle of the nvif object
teardown:

if (chan->fence)
nouveau_fence(chan->cli->drm)->context_del(chan);
...
nvif_object_dtor(&chan->vram);
nvif_event_dtor(&chan->kill);

The subscribed handler is nouveau_channel_killed(), which calls
nouveau_channel_kill() and from there nouveau_fence_context_kill() on
chan->fence. A kill event delivered in that window takes fctx->lock and
walks fctx->pending on a fence context that context_del() has already
freed.

Nothing reaches this below Fermi today, because the subscription is
gated on FERMI_CHANNEL_GPFIFO and nothing kills a channel there. On
Fermi and newer the window is real but narrow, since a kill has to land
exactly while the channel is being destroyed. That is reason enough on
its own, which is why this carries a Fixes: tag. The last patch in this
series subscribes Tesla channels as well; nothing kills those today, so
it does not widen the exposure now, but it is the groundwork for a
recovery path that would, and the ordering is better fixed before that
lands than alongside it.

Drop the subscription before anything it depends on is torn down.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free in the nouveau driver leading to a kernel crash (Denial of Service) and potential local privilege escalation
Action: Apply Patch
AI Analysis

Impact

The Linux kernel’s nouveau DRM driver unsubscribes from the channel‑kill event after deleting the fence context, allowing the event handler to access memory that has already been freed. If a channel kill occurs during this narrow window the unreleased context is referenced, which can trigger a kernel panic. Such a crash can be leveraged locally to gain elevated privileges or simply cause a denial of service to the system.

Affected Systems

The vulnerability affects any Linux system that uses the Linux kernel with the nouveau graphics driver (the upstream kernel). No specific impacted kernel versions are listed, but all kernels that have not yet integrated the patch are susceptible. Updating to a patched kernel removes the flaw.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity. The EPSS score of less than 1% suggests that exploitation, while theoretically possible, is not common or widely seen. The vulnerability is not yet in the CISA KEV catalog. The attack vector appears to be local, requiring a user or process that can trigger a GPU channel kill event. If such an event occurs during channel teardown, the resulting kernel crash can be abused for privilege escalation. In practice, the window is narrow, making successful exploitation difficult.

Generated by OpenCVE AI on September 18, 2026 at 09:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel version that includes the nouveau driver patch addressing the use‑after‑free.
  • If a kernel upgrade cannot be performed immediately, disable the nouveau driver to avoid executing the vulnerable code by adding a blacklist entry (e.g., "blacklist nouveau") to a modprobe configuration file and rebooting.
  • While running a vulnerable kernel, monitor kernel logs for GPU‑related crashes and apply patches as soon as they are released; tools like dmesg can help identify "nouveau" or "nvidia" error messages.

Generated by OpenCVE AI on September 18, 2026 at 09:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: unsubscribe the channel-kill event before the fence context nouveau_channel_del() tears the fence context down first and only drops the channel-kill subscription later, in the middle of the nvif object teardown: if (chan->fence) nouveau_fence(chan->cli->drm)->context_del(chan); ... nvif_object_dtor(&chan->vram); nvif_event_dtor(&chan->kill); The subscribed handler is nouveau_channel_killed(), which calls nouveau_channel_kill() and from there nouveau_fence_context_kill() on chan->fence. A kill event delivered in that window takes fctx->lock and walks fctx->pending on a fence context that context_del() has already freed. Nothing reaches this below Fermi today, because the subscription is gated on FERMI_CHANNEL_GPFIFO and nothing kills a channel there. On Fermi and newer the window is real but narrow, since a kill has to land exactly while the channel is being destroyed. That is reason enough on its own, which is why this carries a Fixes: tag. The last patch in this series subscribes Tesla channels as well; nothing kills those today, so it does not widen the exposure now, but it is the groundwork for a recovery path that would, and the ordering is better fixed before that lands than alongside it. Drop the subscription before anything it depends on is torn down.
Title drm/nouveau: unsubscribe the channel-kill event before the fence context
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:38:48.708Z

Reserved: 2026-09-11T19:38:34.767Z

Link: CVE-2026-89803

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:45.227

Modified: 2026-09-16T15:18:09.993

Link: CVE-2026-89803

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:30:06Z

Weaknesses