PT-2026-93443 · Linux · Linux Kernel

CVE-2026-89802

·

Published

2026-09-16

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A NULL pointer dereference exists in the drm/nouveau/uvmm component. In nouveau uvmm bind job submit(), the OP MAP SPARSE case creates a region but leaves the op->ops variable as NULL. If a subsequent operation within the same job fails, the reverse unwind loop calls drm gpuva ops free() using op->ops without validation. Because drm gpuva ops free() immediately dereferences the argument via list for each entry safe on &ops->list, a NULL value leads to a system crash (oops). This path is accessible to any user holding a render-node file descriptor due to the NOUVEAU VM BIND permission being set to DRM RENDER ALLOW.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101243
CVE-2026-89802
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel