CVE-2026-89803
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/nouveau: unsubscribe the channel-kill event before the fence context
nouveau_channel_del() tears the fence context down first and only drops the channel-kill subscription later, in the middle of the nvif object teardown:
if (chan->fence)
nouveau_fence(chan->cli->drm)->context_del(chan);
...
nvif_object_dtor(&chan->vram);
nvif_event_dtor(&chan->kill);
The subscribed handler is nouveau_channel_killed(), which calls nouveau_channel_kill() and from there nouveau_fence_context_kill() on chan->fence. A kill event delivered in that window takes fctx->lock and walks fctx->pending on a fence context that context_del() has already freed.
Nothing reaches this below Fermi today, because the subscription is gated on FERMI_CHANNEL_GPFIFO and nothing kills a channel there. On Fermi and newer the window is real but narrow, since a kill has to land exactly while the channel is being destroyed. That is reason enough on its own, which is why this carries a Fixes: tag. The last patch in this series subscribes Tesla channels as well; nothing kills those today, so it does not widen the exposure now, but it is the groundwork for a recovery path that would, and the ordering is better fixed before that lands than alongside it.
Drop the subscription before anything it depends on is torn down.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | ea13e5abf807ea912ce84eef6a1946b9a38c6508 < f5a79a9ebfbafb87ca7a896e8d6b5f33a98d097e | affected |
| Linux | Linux | ea13e5abf807ea912ce84eef6a1946b9a38c6508 < f3830fdd6930e233d727f29eee1617f7e6a0e9e5 | affected |
| Linux | Linux | ea13e5abf807ea912ce84eef6a1946b9a38c6508 < 1fef7553dc628295c1208a4f2ac2094c62886e5d | affected |
| Linux | Linux | ea13e5abf807ea912ce84eef6a1946b9a38c6508 < 511585987d27d8cb668acebd399fc4deda23404c | affected |
| Linux | Linux | 5.6 | affected |
| Linux | Linux | 0 < 5.6 | unaffected |
| Linux | Linux | 6.12.110 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.51 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.5 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/f5a79a9ebfbafb87ca7a896e8d6b5f33a98d097e
- https://git.kernel.org/stable/c/f3830fdd6930e233d727f29eee1617f7e6a0e9e5
- https://git.kernel.org/stable/c/1fef7553dc628295c1208a4f2ac2094c62886e5d
- https://git.kernel.org/stable/c/511585987d27d8cb668acebd399fc4deda23404c
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.