SB2026050902 - Improper Check for Unusual or Exceptional Conditions in Linux kernel drm nouveau driver
Published: May 9, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-43381)
CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of runtime-suspended devices in nouveau dpcd aux transfer handling when accessing /dev/drm_dp_* while the device is asleep. A local user can access the drm dp device interface while the device is runtime suspended to cause a denial of service.
The issue is triggered when the GPU device is in a runtime suspended state.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/178df7c91e6c202579284df9f79d1592a514cdcf
- https://git.kernel.org/stable/c/24639553a016578222ac597db924dfb6fa5ec8b5
- https://git.kernel.org/stable/c/4df518aa196085909fd7e32518ecd27fba60ed69
- https://git.kernel.org/stable/c/6bdd2d70c338d52c387d3b3aadc596784ae81b01
- https://git.kernel.org/stable/c/8f3c6f08ababad2e3bdd239728cf66a9949446b4
- https://git.kernel.org/stable/c/ad8fa5bff53f5d1f8394f996850da8ce070eaee3
- https://git.kernel.org/stable/c/cd24cab2023aa46b595bc6b9cc39d8973d9d0a8c
- https://git.kernel.org/stable/c/fad178ae894930520519ead3c8e0150641466360