CVE-2026-89803
In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: unsubscribe the channel-kill event before the fence contex
CVSS
7.8
Alto
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 16 sept 2026 · Última mod.: 16 sept 2026
Sin historial EPSS suficiente todavía.
In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: unsubscribe the channel-kill event before the fence context nouveau_channel_del() tears the fence context down first and only drops the channel-kill subscription later, in the middle of the nvif object teardown: if (chan->fence) nouveau_fence(chan->cli->drm)->context_del(chan); ... nvif_object_dtor(&chan->vram); nvif_event_dtor(&chan->kill); The subscribed handler is nouveau_channel_killed(), which calls nouveau_channel_kill() and from there nouveau_fence_context_kill() on chan->fence. A kill event delivered in that window takes fctx->lock and walks fctx->pending on a fence context that context_del() has already freed. Nothing reaches this below Fermi today, because the subscription is gated on FERMI_CHANNEL_GPFIFO and nothing kills a channel there. On Fermi and newer the window is real but narrow, since a kill has to land exactly while the channel is being destroyed. That is reason enough on its own, which is why this carries a Fixes: tag. The last patch in this series subscribes Tesla channels as well; nothing kills those today, so it does not widen the exposure now, but it is the groundwork for a recovery path that would, and the ordering is better fixed before that lands than alongside it. Drop the subscription before anything it depends on is torn down.
- git.kernel.orghttps://git.kernel.org/stable/c/1fef7553dc628295c1208a4f2ac2094c62886e5d
- git.kernel.orghttps://git.kernel.org/stable/c/511585987d27d8cb668acebd399fc4deda23404c
- git.kernel.orghttps://git.kernel.org/stable/c/f3830fdd6930e233d727f29eee1617f7e6a0e9e5
- git.kernel.orghttps://git.kernel.org/stable/c/f5a79a9ebfbafb87ca7a896e8d6b5f33a98d097e
Sin CVEs relacionados por CWE o producto.