{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.2.6-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  drm/nouveau/dmem: fix callocated underflow on large folio split  nouveau_dmem_folio_free() drops chunk-\u003ecallocated once per freed folio, while a large (compound) device-private folio is only counted once when it is allocated.  When such a folio is split, the mm core invokes -\u003efolio_split() (nouveau_dmem_folio_split()) once for each new sub-folio, but the hook only fixes up the sub-folio metadata and leaves chunk-\u003ecallocated unchanged.  Each resulting sub-folio is later freed separately, so after a split the single allocation (+1) is met by N frees (-N), leaving chunk-\u003ecallocated short by N-1.  On the first split/free cycle it underflows: WARN_ON(!chunk-\u003ecallocated) fires, the unsigned counter wraps and never returns to zero, so the chunk can no longer be reclaimed (nouveau_dmem_fini() also warns on the leaked count).  Account for the new sub-folio in the split hook, under the same lock as nouveau_dmem_folio_free(), so the count stays balanced.",
  "id": "DEBIAN-CVE-2026-93233",
  "modified": "2026-09-25T04:47:29.897693920Z",
  "published": "2026-09-24T16:17:18.887Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-93233"
    }
  ],
  "upstream": [
    "CVE-2026-93233"
  ]
}