PT-2026-93445 · Linux · Linux Kernel

CVE-2026-89804

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the drm/nouveau/dmem component where device-private Transparent Huge Page (THP) migration maps buffers using page size() and records the length in dma info->size. For compound folios, the dma unmap page() function is incorrectly called with a literal PAGE SIZE instead of the recorded size within the nouveau dmem migrate to ram() function on the success path and the nouveau dmem migrate copy one() function on the copy-error path. This results in unmapping less memory than was originally mapped for folios with an order greater than 0, leading to a leak of the remaining IOMMU/IOVA mapping.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-89804
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel