Use-after-free in Linux kernel - CVE-2026-89803
Published: September 17, 2026
Vulnerability details
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to a use-after-free in the Nouveau channel teardown handler when a channel-kill event is delivered during channel destruction. A local user can trigger a channel-kill event during the teardown window to execute arbitrary code.
The issue affects Fermi and newer GPUs; the kill event must occur while the channel is being destroyed.