---
id: CVE-2026-93233
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  drm/nouveau/dmem: fix callocated underflow on large folio split

  nouveau_dmem_folio_free() drops chunk->callocated once per freed folio,
  while a large (compound) device…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  drm/nouveau/dmem: fix callocated underflow on large folio split

  nouveau_dmem_folio_free() drops chunk->callocated once per freed folio,
  while a large (compound) device…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= c3228747107705d47c7e9a03598a434a0380cb73 <
    0163b92946d0a7c816f619c57a4d9867954dd106
  - >-
    Linux >= c3228747107705d47c7e9a03598a434a0380cb73 <
    c2256c044a1df39c8aad4dd2d6f709b2533e2d7a
  - Linux 6.19
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T16:17:18.887'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93233'
references:
  - url: 'https://git.kernel.org/stable/c/0163b92946d0a7c816f619c57a4d9867954dd106'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c2256c044a1df39c8aad4dd2d6f709b2533e2d7a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-24T15:45:56.665Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

drm/nouveau/dmem: fix callocated underflow on large folio split

nouveau_dmem_folio_free() drops chunk->callocated once per freed folio,
while a large (compound) device-private folio is only counted once when
it is allocated.  When such a folio is split, the mm core invokes
->folio_split() (nouveau_dmem_folio_split()) once for each new
sub-folio, but the hook only fixes up the sub-folio metadata and leaves
chunk->callocated unchanged.

Each resulting sub-folio is later freed separately, so after a split
the single allocation (+1) is met by N frees (-N), leaving
chunk->callocated short by N-1.  On the first split/free cycle it
underflows: WARN_ON(!chunk->callocated) fires, the unsigned counter
wraps and never returns to zero, so the chunk can no longer be
reclaimed (nouveau_dmem_fini() also warns on the leaked count).

Account for the new sub-folio in the split hook, under the same lock as
nouveau_dmem_folio_free(), so the count stays balanced.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
