-

CVE-2026-89802

drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op

In the Linux kernel, the following vulnerability has been resolved:

drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op

Each bind_job_op is zeroed by kzalloc_obj() in bind_job_op_from_uop(),
and the OP_MAP_SPARSE case in nouveau_uvmm_bind_job_submit() only creates
a region, so op->ops stays NULL for a successfully processed sparse map.

If a later op in the same job fails, the reverse unwind loop revisits that
op and calls drm_gpuva_ops_free(&uvmm->base, op->ops) unconditionally.
drm_gpuva_ops_free() dereferences its argument right away
(list_for_each_entry_safe on &ops->list), so a NULL op->ops oopses. The
path is reachable by any render-node fd holder, since NOUVEAU_VM_BIND is
DRM_RENDER_ALLOW.

Guard the free with IS_ERR_OR_NULL(), as nouveau_uvmm_bind_job_cleanup()
already does for the identical free.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version b88baab828713ce0b49b185444b2ee83bed373a8
Version < 3bf493cf7ed0c2b3df728977a257e0d99b4db1c6
Status affected
Version b88baab828713ce0b49b185444b2ee83bed373a8
Version < b7dc03e09313d22a6d230b759de3b05d504c008f
Status affected
Version b88baab828713ce0b49b185444b2ee83bed373a8
Version < 3857238de6bce6c1573e8cb86c37b067e5208f05
Status affected
Version b88baab828713ce0b49b185444b2ee83bed373a8
Version < 412a6ceb56d501ef2f8202e26ab4b5d4dfbca566
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.6
Status affected
Version 0
Version < 6.6
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.102
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/3bf493cf7ed0c2b3df728977a257e0d99b4db1c6
https://git.kernel.org/stable/c/b7dc03e09313d22a6d230b759de3b05d504c008f
https://git.kernel.org/stable/c/3857238de6bce6c1573e8cb86c37b067e5208f05
https://git.kernel.org/stable/c/412a6ceb56d501ef2f8202e26ab4b5d4dfbca566