Executive brief
The Nouveau GPU driver in the Linux kernel contains a race condition in the gem info ioctl that can lead to accessing memory that has already been freed. An attacker with access to GPU operations could exploit this to cause a kernel crash or potentially execute code with kernel privileges.
Technical details
The vulnerability is a use-after-free race condition in the non-UVMM path of the Nouveau GEM info ioctl handler. The vulnerable code performs a virtual memory address (vma) lookup without holding a proper lock on the buffer object, allowing the gem close path to deallocate the vma between the lookup and its use. The attack requires local access to GPU device operations via the DRM ioctl interface. The fix reserves the buffer object during the vma lookup and access, preventing the race condition. Patches have been merged upstream in commit 5e17160d41d92823f3379c1982e1369680c5ce4d.
Affected products
- Linux Linux Kernel multiple versions including 4.x, 5.x, 6.x, and 7.x series
Timeline
- 2026-09-11: disclosed: CVE published
- 2026-06-12: patched: Upstream fix commit by Dave Airlie
- 2026-09-07: patched: Merged to stable branches