← All Advisories

Linux Kernel DRM Nouveau Tears Down the Fence Context Before Unsubscribing Channel-Kill Events, Creating a Use-After-Free Window

Last refreshed2026-09-29

Status: NEW  |  Advisory ID: CVE-2026-89803

Key Details

CVECVE-2026-89803
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-09-16
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.

What to Know

In the Linux kernel, the following vulnerability has been resolved:

drm/nouveau: unsubscribe the channel-kill event before the fence context

nouveau_channel_del() tears the fence context down first and only drops

the channel-kill subscription later, in the middle of the nvif object

teardown:

if (chan->fence)

nouveau_fence(chan->cli->drm)->context_del(chan);

...

nvif_object_dtor(&chan->vram);

nvif_event_dtor(&chan->kill);

The subscribed handler is nouveau_channel_killed(), which calls

nouveau_channel_kill() and from there nouveau_fence_context_kill() on

chan->fence. A kill event delivered in that window takes fctx->lock and

walks fctx->pending on a fence context that context_del() has already

freed.

Nothing reaches this below Fermi today, because the subscription is

gated on FERMI_CHANNEL_GPFIFO and nothing kills a channel there. On

Fermi and newer the window is real but narrow, since a kill has to land

exactly while the channel is being destroyed. That is reason enough on

its own, which is why this carries a Fixes: tag. The last patch in this

series subscribes Tesla channels as well; nothing kills those today, so

it does not widen the exposure now, but it is the groundwork for a

recovery path that would, and the ordering is better fixed before that

lands than alongside it.

Drop the subscription before anything it depends on is torn down. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-89803
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-89803