NULL pointer dereference in Linux kernel - CVE-2026-89802
Published: September 17, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in the reverse unwind loop of nouveau_uvmm_bind_job_submit() when processing a bind job containing a successful sparse mapping operation followed by a later failing operation. A local user can submit a crafted bind job to cause a denial of service.