CVE-2026-89590
Received Received - Intake

Use-After-Free in Linux Kernel Rocket Accelerator

Vulnerability report for CVE-2026-89590, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: accel/rocket: Fix error path handling in rocket_job_run() In rocket_job_run(), after taking an extra fence reference for job->done_fence via dma_fence_get(), the error paths have three bugs: - The dma_fence reference held by job->done_fence is never released, causing a reference leak. - pm_runtime_get_sync() increments the usage counter even on failure, but the error path does not decrement it, leaking the runtime PM reference and preventing the NPU from suspending. - A valid but unsignaled fence is returned to the DRM scheduler, which triggers WARN("Fence ... released with pending signals!") when the scheduler drops its reference. Fix by replacing pm_runtime_get_sync() with pm_runtime_resume_and_get() which auto-balances the usage counter on failure, releasing both fence references on error, and returning ERR_PTR(ret) instead of the unsignaled fence. [tomeu: Refactored error paths to use consolidated goto labels]

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Linux kernel's accel/rocket component, specifically in the rocket_job_run() function. It involves incorrect error handling that causes reference leaks and improper resource management. The issues include not releasing a DMA fence reference, leaking a runtime PM reference, and returning an invalid fence to the DRM scheduler.

Detection Guidance

This vulnerability is specific to the Linux kernel's accel/rocket subsystem and does not have network-based detection methods. Detection requires checking the kernel version and examining the rocket_job_run() function for the described error handling issues. Use commands like 'uname -a' to check kernel version and 'grep rocket_job_run /proc/kallsyms' to locate the function.

Impact Analysis

This vulnerability could lead to system instability or crashes due to resource leaks. The runtime PM reference leak may prevent the NPU from suspending properly, causing performance issues or unexpected behavior. The invalid fence return might trigger kernel warnings or errors in the DRM scheduler.

Compliance Impact

This vulnerability is specific to the Linux kernel's accel/rocket subsystem and involves reference leaks and improper error handling in the rocket_job_run() function. It does not directly relate to data privacy, security controls, or compliance requirements under standards like GDPR or HIPAA.

Mitigation Strategies

Apply the latest kernel patch that fixes the rocket_job_run() error handling. Update to a kernel version containing the fix or backport the patch manually. Monitor system logs for WARN messages about fence releases to identify affected systems.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89590. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart