Database/Kernel, userspace & hypervisor
Linux kernel (drivers/gpu/drm/nouveau): A buffer object imported over PRIME leaves a dangling pointer behind, and the
Impact
A buffer object imported over PRIME leaves a dangling pointer behind, and the deferred TTM delete worker later walks it - the oops trace shows classic freed-slab poison being dereferenced. A tenant driving dma-buf import and release controls when the freed object is touched, turning it into a use-after-free in kernel worker context.
Who can reach it
A tenant process holding /dev/dri/renderD* on a nouveau GPU imports and releases dma-bufs in a loop; the fault lands asynchronously in the TTM delayed-delete workqueue, so it is not confined to the tenant's own task. Conditional on the node using the upstream nouveau driver.
What to do
Boot a kernel carrying the nouveau prime lifetime fix below. Interim: on nouveau nodes, withhold /dev/dri/renderD* from untrusted tenants, or forbid dma-buf import for workloads that do not need buffer sharing across devices.
References
Related entries
- Linux kernel (drivers/gpu/drm/nouveau): When the device-to-host copy behind a page fault silently fails, the faultCVE-2024-50096 · Linux kernel (drivers/gpu/drm/nouveau)High
- Linux kernel (drivers/gpu/drm/nouveau): Calling the legacy pushbuf submission ioctl on a client that has VM_BINDCVE-2024-35786 · Linux kernel (drivers/gpu/drm/nouveau)Medium
- Linux kernel (drivers/gpu/drm/nouveau): Importing a dma-buf whose backing buffer object fails to initialize leaves theCVE-2022-50454 · Linux kernel (drivers/gpu/drm/nouveau)High
- Linux kernel (drivers/gpu/drm/nouveau): Nouveau's VM_BIND remap path miscalculates the address and range of the unmapCVE-2024-36018 · Linux kernel (drivers/gpu/drm/nouveau)High
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A use-after-free in the amdkfd (KFD compute driverCVE-2025-37854 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
- Linux kernel (drivers/gpu/drm/xe): The error path of the Xe VRAM clear helper waits on a fence pointer that is onlyCVE-2025-37869 · Linux kernel (drivers/gpu/drm/xe)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.