CVE-2026-89800
CVE CVE-2026-89800EUVD EUVD-2026-80400Published 2026-09-16T10:30:33.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE A successful OP_UNMAP_SPARSE marks its region dirty with nouveau_uvma_region_dirty() and defers the teardown to nouveau_uvmm_bind_job_cleanup(); it does not remove the region from uvmm->region_mt. If a later op in the job fails, the unwind path never clears reg->dirty (set in one place, cleared nowhere) and sets op->reg = NULL, so cleanup skips the teardown. The region is left in the tree with dirty set and its completion never signalled. Later binds over that range then fail permanently -- -ENOENT or -EINVAL from the dirty checks, or an unkillable wait_for_completion() in bind_validate_region() -- for the lifetime of the uvmm. Clear reg->dirty when the unwind reverts the sparse unmap, restoring the region to the state it was found in.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux b88baab828713ce0b49b185444b2ee83bed373a8 <c60033c172420179b7bbb3d1f843f8dc90164dc5; b88baab828713ce0b49b185444b2ee83bed373a8 <a129b2b875c148aba233ace8447a0c36ca3bae07; 6.6; patch: 6.18.51; patch: 6.6.157; b88baab828713ce0b49b185444b2ee83bed373a8 <38a62306c4266bcb3cd89e33c7111ee33096ebb3; b88baab828713ce0b49b185444b2ee83bed373a8 <196ce9e5e93202da097062be24e404984dbc5ac2; patch: 0; patch: 7.3-rc2; patch: 6.12.110; patch: 7.2.5; b88baab828713ce0b49b185444b2ee83bed373a8 <1101cbfe7f342e5eaaf7444965d4f1215abdac4c
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.