CVE-2026-89553

Source
https://cve.org/CVERecord?id=CVE-2026-89553
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89553.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89553
Downstream
Published
2026-09-11T19:44:26Z
Modified
2026-09-13T03:47:19Z
Summary
nouveau/gem: reserve the bo in the info ioctl around the vma lookup
Details

In the Linux kernel, the following vulnerability has been resolved:

nouveau/gem: reserve the bo in the info ioctl around the vma lookup

In the non-uvmm path, there could be a race between the info lookup finding the vma, and the gem close path closing the vma leading to a use-after-free.

Spotted with the help of Opus 4.6.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89553.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e758a3111914af7ee4351be86f1ac0efe87ed06e
Fixed
208867763843aa82efcbe3b771f1b8e6c7aa820a
Fixed
ff110e85837d7ecd83f36078107be240ff5ae409
Fixed
e60466011ac3a6b8045e6cc3c2cbb30d58039d2e
Fixed
5e17160d41d92823f3379c1982e1369680c5ce4d

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89553.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.1.0
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89553.json"