๐Ÿ” CVE Alert

CVE-2026-89802

UNKNOWN 0.0

drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op Each bind_job_op is zeroed by kzalloc_obj() in bind_job_op_from_uop(), and the OP_MAP_SPARSE case in nouveau_uvmm_bind_job_submit() only creates a region, so op->ops stays NULL for a successfully processed sparse map. If a later op in the same job fails, the reverse unwind loop revisits that op and calls drm_gpuva_ops_free(&uvmm->base, op->ops) unconditionally. drm_gpuva_ops_free() dereferences its argument right away (list_for_each_entry_safe on &ops->list), so a NULL op->ops oopses. The path is reachable by any render-node fd holder, since NOUVEAU_VM_BIND is DRM_RENDER_ALLOW. Guard the free with IS_ERR_OR_NULL(), as nouveau_uvmm_bind_job_cleanup() already does for the identical free.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
b88baab828713ce0b49b185444b2ee83bed373a8 < 3bf493cf7ed0c2b3df728977a257e0d99b4db1c6 b88baab828713ce0b49b185444b2ee83bed373a8 < b7dc03e09313d22a6d230b759de3b05d504c008f b88baab828713ce0b49b185444b2ee83bed373a8 < 3857238de6bce6c1573e8cb86c37b067e5208f05 b88baab828713ce0b49b185444b2ee83bed373a8 < 412a6ceb56d501ef2f8202e26ab4b5d4dfbca566
Linux / Linux
6.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/3bf493cf7ed0c2b3df728977a257e0d99b4db1c6 git.kernel.org: https://git.kernel.org/stable/c/b7dc03e09313d22a6d230b759de3b05d504c008f git.kernel.org: https://git.kernel.org/stable/c/3857238de6bce6c1573e8cb86c37b067e5208f05 git.kernel.org: https://git.kernel.org/stable/c/412a6ceb56d501ef2f8202e26ab4b5d4dfbca566