« Volver al listado

CVE-2026-93233

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

drm/nouveau/dmem: fix callocated underflow on large folio split

nouveau_dmem_folio_free() drops chunk->callocated once per freed folio, while a large (compound) device-private folio is only counted once when it is allocated. When such a folio is split, the mm core invokes ->folio_split() (nouveau_dmem_folio_split()) once for each new sub-folio, but the hook only fixes up the sub-folio metadata and leaves chunk->callocated unchanged.

Each resulting sub-folio is later freed separately, so after a split the single allocation (+1) is met by N frees (-N), leaving chunk->callocated short by N-1.

Leer descripción completaMostrar menos

On the first split/free cycle it underflows: WARN_ON(!chunk->callocated) fires, the unsigned counter wraps and never returns to zero, so the chunk can no longer be reclaimed (nouveau_dmem_fini() also warns on the leaked count).

Account for the new sub-folio in the split hook, under the same lock as nouveau_dmem_folio_free(), so the count stays balanced.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93233",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "c3228747107705d47c7e9a03598a434a0380cb73",
              "lessThan": "0163b92946d0a7c816f619c57a4d9867954dd106",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c3228747107705d47c7e9a03598a434a0380cb73",
              "lessThan": "c2256c044a1df39c8aad4dd2d6f709b2533e2d7a",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/nouveau/nouveau_dmem.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/nouveau/nouveau_dmem.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-24T16:17:18.887",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0163b92946d0a7c816f619c57a4d9867954dd106",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c2256c044a1df39c8aad4dd2d6f709b2533e2d7a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/nouveau/dmem: fix callocated underflow on large folio split\n\nnouveau_dmem_folio_free() drops chunk->callocated once per freed folio,\nwhile a large (compound) device-private folio is only counted once when\nit is allocated.  When such a folio is split, the mm core invokes\n->folio_split() (nouveau_dmem_folio_split()) once for each new\nsub-folio, but the hook only fixes up the sub-folio metadata and leaves\nchunk->callocated unchanged.\n\nEach resulting sub-folio is later freed separately, so after a split\nthe single allocation (+1) is met by N frees (-N), leaving\nchunk->callocated short by N-1.  On the first split/free cycle it\nunderflows: WARN_ON(!chunk->callocated) fires, the unsigned counter\nwraps and never returns to zero, so the chunk can no longer be\nreclaimed (nouveau_dmem_fini() also warns on the leaked count).\n\nAccount for the new sub-folio in the split hook, under the same lock as\nnouveau_dmem_folio_free(), so the count stays balanced."
    }
  ],
  "lastModified": "2026-09-24T16:17:18.887",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}