# CVE-2026-89553

## Summary

- **CVE ID:** CVE-2026-89553
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 14, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

nouveau/gem: reserve the bo in the info ioctl around the vma lookup

In the non-uvmm path, there could be a race between the info lookup
finding the vma, and the gem close path closing the vma leading
to a use-after-free.

Spotted with the help of Opus 4.6.

## Affected Products

- Linux — Linux (e758a3111914af7ee4351be86f1ac0efe87ed06e)
- Linux — Linux (3.1)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/208867763843aa82efcbe3b771f1b8e6c7aa820a)
- [CNA](https://git.kernel.org/stable/c/ff110e85837d7ecd83f36078107be240ff5ae409)
- [CNA](https://git.kernel.org/stable/c/e60466011ac3a6b8045e6cc3c2cbb30d58039d2e)
- [CNA](https://git.kernel.org/stable/c/5e17160d41d92823f3379c1982e1369680c5ce4d)
- [CNA](https://git.kernel.org/stable/c/e05c28bd6043d0fd0bea9c3fc49300a8871a1a81)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.13%
- **EPSS Percentile:** 3.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._