-

CVE-2026-89800

drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE

In the Linux kernel, the following vulnerability has been resolved:

drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE

A successful OP_UNMAP_SPARSE marks its region dirty with
nouveau_uvma_region_dirty() and defers the teardown to
nouveau_uvmm_bind_job_cleanup(); it does not remove the region from
uvmm->region_mt.

If a later op in the job fails, the unwind path never clears reg->dirty
(set in one place, cleared nowhere) and sets op->reg = NULL, so cleanup
skips the teardown. The region is left in the tree with dirty set and its
completion never signalled. Later binds over that range then fail
permanently -- -ENOENT or -EINVAL from the dirty checks, or an unkillable
wait_for_completion() in bind_validate_region() -- for the lifetime of
the uvmm.

Clear reg->dirty when the unwind reverts the sparse unmap, restoring the
region to the state it was found in.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version b88baab828713ce0b49b185444b2ee83bed373a8
Version < a129b2b875c148aba233ace8447a0c36ca3bae07
Status affected
Version b88baab828713ce0b49b185444b2ee83bed373a8
Version < 196ce9e5e93202da097062be24e404984dbc5ac2
Status affected
Version b88baab828713ce0b49b185444b2ee83bed373a8
Version < 1101cbfe7f342e5eaaf7444965d4f1215abdac4c
Status affected
Version b88baab828713ce0b49b185444b2ee83bed373a8
Version < c60033c172420179b7bbb3d1f843f8dc90164dc5
Status affected
Version b88baab828713ce0b49b185444b2ee83bed373a8
Version < 38a62306c4266bcb3cd89e33c7111ee33096ebb3
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.6
Status affected
Version 0
Version < 6.6
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.102
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/a129b2b875c148aba233ace8447a0c36ca3bae07
https://git.kernel.org/stable/c/196ce9e5e93202da097062be24e404984dbc5ac2
https://git.kernel.org/stable/c/1101cbfe7f342e5eaaf7444965d4f1215abdac4c
https://git.kernel.org/stable/c/c60033c172420179b7bbb3d1f843f8dc90164dc5
https://git.kernel.org/stable/c/38a62306c4266bcb3cd89e33c7111ee33096ebb3