PT-2026-93445 · Linux · Linux Kernel
CVE-2026-89804
·
Published
2026-09-16
·
Updated
2026-09-24
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the
drm/nouveau/dmem component where device-private Transparent Huge Page (THP) migration maps buffers using page size() and records the length in dma info->size. For compound folios, the dma unmap page() function is incorrectly called with a literal PAGE SIZE instead of the recorded size within the nouveau dmem migrate to ram() function on the success path and the nouveau dmem migrate copy one() function on the copy-error path. This results in unmapping less memory than was originally mapped for folios with an order greater than 0, leading to a leak of the remaining IOMMU/IOVA mapping.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel