Updated: 2026-02-27 00:33:24.057811
Description:
There is a flaw reported in the Linux kernel in versions before 5.9 in drivers/gpu/drm/nouveau/nouveau_sgdma.c in nouveau_sgdma_create_ttm in Nouveau DRM subsystem. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker with a local account with a root privilege, can leverage this vulnerability to escalate privileges and execute code in the context of the kernel.
| Links | NIST | CIRCL | RHEL | Ubuntu |
| Severity | Score | |
|---|---|---|
| CVSS Version 2.x | HIGH | 7.2 |
| CVSS Version 3.x | MEDIUM | 6.7 |
| OS name | Project name | Version | Score | Severity | Status | Errata | Last updated | Statement |
|---|---|---|---|---|---|---|---|---|
| CentOS 6 ELS | kernel | 2.6.32 | 6.7 | MEDIUM | Released | CLSA-2021:1632262296 | 2022-05-05 12:01:40 | |
| CentOS 7 ELS | kernel | 3.10.0 | 6.7 | MEDIUM | Released | CLSA-2024:1720468480 | 2024-07-23 17:34:23 | |
| CentOS 8.4 ELS | kernel | 4.18.0 | 6.7 | MEDIUM | Ignored | 2022-04-29 15:33:55 | Ignored due to low severity | |
| CentOS 8.5 ELS | kernel | 4.18.0 | 6.7 | MEDIUM | Not Vulnerable | 2025-10-24 07:18:53 | Not affected: CVE-2021-20292 is limited to the Nouveau NVIDIA GPU driver and is only reachable when ... | |
| CloudLinux 6 ELS | kernel | 2.6.32 | 6.7 | MEDIUM | Ignored | 2022-04-29 15:33:54 | Ignored due to low severity | |
| Oracle Linux 6 ELS | kernel | 2.6.32 | 6.7 | MEDIUM | Released | CLSA-2022:1669850228 | 2022-11-30 19:57:54 | |
| RHEL 7 ELS | kernel | 3.10.0 | 6.7 | MEDIUM | Released | CLSA-2025:1750353839 | 2025-06-20 00:28:25 | |
| Ubuntu 16.04 ELS | linux-hwe | 4.15.0 | 6.7 | MEDIUM | Already Fixed | 2022-09-28 03:36:18 | ||
| Ubuntu 16.04 ELS | linux | 4.4.0 | 6.7 | MEDIUM | Released | 2022-04-29 15:33:55 | ||
| Ubuntu 18.04 ELS | linux | 4.15.0 | 6.7 | MEDIUM | Ignored | 2023-03-02 04:04:04 | Ignored due to low severity |