Description
In the Linux kernel, the following vulnerability has been resolved:

drm/nouveau/dmem: fix mismatched DMA unmap size for large folios

Device-private THP migration maps migration buffers with page_size()
and records that length in dma_info->size. For a compound folio
page_size() is PAGE_SIZE << order, but two teardown sites still pass a
literal PAGE_SIZE to dma_unmap_page():

- nouveau_dmem_migrate_to_ram() on the success path, and
- nouveau_dmem_migrate_copy_one() on the copy-error path.

For an order > 0 folio this unmaps less than was mapped, leaking the
remainder of the IOMMU/IOVA mapping. The other unmap sites, in
nouveau_dmem_migrate_chunk() and nouveau_dmem_evict_chunk(), already
use the saved size; use it here too.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Data leakage via improper DMA unmap of large folios
Action: Apply Patch
AI Analysis

Impact

The Linux kernel's Nouveau driver contains a flaw where the DMA unmap size is mismatched for large compound folios during device migration. The driver records the full mapping size but later unmaps only a single PAGE_SIZE, leaving part of the IOMMU/IOVA mapping active. This improper resource cleanup can allow other devices or processes to access unmapped memory, effectively leaking data.

Affected Systems

All Linux kernels that include the affected version of the Nouveau driver are vulnerable when Transparent HugePages are enabled for device migration. The vulnerability applies to any kernel compiled before the patch. It is inferred that systems using NVIDIA graphics hardware with the Nouveau driver enabled may be affected, though the CVE data does not explicitly mention hardware.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, while the EPSS score of < 1% suggests that exploitation is unlikely at present. The vulnerability is not in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need local kernel privileges or sufficient device access to trigger migration or copy operations on the GPU. The overall risk remains moderate, primarily affecting environments with privileged GPU usage and insufficient IOMMU isolation.

Generated by OpenCVE AI on September 18, 2026 at 11:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel patch that corrects the DMA unmap size mismatch in the Nouveau driver
  • Upgrade to a kernel version that incorporates the fixed Nouveau driver
  • If patching cannot be performed immediately, disable the Nouveau driver or blacklist it to prevent the vulnerability from being active

Generated by OpenCVE AI on September 18, 2026 at 11:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-775

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/dmem: fix mismatched DMA unmap size for large folios Device-private THP migration maps migration buffers with page_size() and records that length in dma_info->size. For a compound folio page_size() is PAGE_SIZE << order, but two teardown sites still pass a literal PAGE_SIZE to dma_unmap_page(): - nouveau_dmem_migrate_to_ram() on the success path, and - nouveau_dmem_migrate_copy_one() on the copy-error path. For an order > 0 folio this unmaps less than was mapped, leaking the remainder of the IOMMU/IOVA mapping. The other unmap sites, in nouveau_dmem_migrate_chunk() and nouveau_dmem_evict_chunk(), already use the saved size; use it here too.
Title drm/nouveau/dmem: fix mismatched DMA unmap size for large folios
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:38:49.967Z

Reserved: 2026-09-11T19:38:34.767Z

Link: CVE-2026-89804

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:45.347

Modified: 2026-09-16T15:18:10.130

Link: CVE-2026-89804

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T11:15:07Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-775

    Missing Release of File Descriptor or Handle after Effective Lifetime