PT-2026-93443 · Linux · Linux Kernel
CVE-2026-89802
·
Published
2026-09-16
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A NULL pointer dereference exists in the
drm/nouveau/uvmm component. In nouveau uvmm bind job submit(), the OP MAP SPARSE case creates a region but leaves the op->ops variable as NULL. If a subsequent operation within the same job fails, the reverse unwind loop calls drm gpuva ops free() using op->ops without validation. Because drm gpuva ops free() immediately dereferences the argument via list for each entry safe on &ops->list, a NULL value leads to a system crash (oops). This path is accessible to any user holding a render-node file descriptor due to the NOUVEAU VM BIND permission being set to DRM RENDER ALLOW.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel