CVE-2026-89801
CVE CVE-2026-89801EUVD EUVD-2026-80401Published 2026-09-16T10:30:34.000ZLast changed 2026-09-16T14:38:47.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE In nouveau_uvmm_bind_job_submit()'s OP_UNMAP_SPARSE arm, op->reg is set from nouveau_uvma_region_find(), which only looks the region up and takes no reference; a region's sole reference is its membership in uvmm->region_mt. Two failure paths leave op->reg set: the -ENOENT check when the region is busy, and the drm_gpuvm_sm_unmap_ops_create() failure. The sibling nouveau_uvmm_sm_unmap_prepare() failure just below clears op->reg; these two do not. unwind_continue steps back one op, so the failing op is skipped by the unwind loop and its op->reg stays set. nouveau_uvmm_bind_job_cleanup() then enters its if (op->reg) branch and calls nouveau_uvma_region_remove() and nouveau_uvma_region_put() on it, dropping the tree's sole reference and freeing a region this job never created. The comment above the cleanup loop documents the broken invariant: op->reg must be NULL on submit failure. This frees a live region on an unrelated failure, reachable single-job when drm_gpuvm_sm_unmap_ops_create() returns -ENOMEM; if another job owns the same region, its cleanup then removes and puts the freed region, a use-after-free. Clear op->reg on both failure paths.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 6.18.51; b88baab828713ce0b49b185444b2ee83bed373a8 <24c25b182d17d1bdfde0088c96bdf6f93e8f46bc; 6.6; b88baab828713ce0b49b185444b2ee83bed373a8 <88114e3a96582882e63b2f73aa7a5a9cf0d5073c; b88baab828713ce0b49b185444b2ee83bed373a8 <ccf930812f23b8259ef64fd3394d53b093e4651a; patch: 6.12.110; patch: 7.3-rc2; patch: 0; b88baab828713ce0b49b185444b2ee83bed373a8 <ba42d8a1c2c7629c61914df11a7d63ac77449ffb; b88baab828713ce0b49b185444b2ee83bed373a8 <4083d24c2636fde7b18076115af52820d203bc57; patch: 6.6.157; patch: 7.2.5
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.