Junglewise Threat Intelligence

CVE-2026-23305: Linux Kernel Rocket accelerator out-of-bounds access in rocket_probe

CVE-2026-23305 · Severity: high · CVSS 7.1 · Published 2026-03-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Rocket accelerator driver, which manages specialized hardware used for computational tasks. If the driver fails to initialize correctly, it does not properly clean up its internal state, which can lead to system instability or unauthorized access to memory. This could allow a local user to crash the system or potentially view sensitive information stored in memory.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the 'accel/rocket' driver within the Linux kernel. The issue occurs in the 'rocket_probe' function when 'rocket_core_init' fails (e.g., due to EPROBE_DEFER). In this error path, the driver fails to decrement the core counter or finalize the DRM device, leading to inconsistent state and subsequent out-of-bounds memory accesses. A local attacker with low privileges could exploit this to cause a denial of service (system crash) or read sensitive kernel memory. Patches have been released for various stable kernel branches including 6.18.y and 6.19.y.

Affected products

  • Linux Linux Kernel 6.18 to 6.18.17, 6.19 to 6.19.7

Timeline

  • 2026-03-25: disclosed
  • 2026-03-25: advisory
  • 2026-01-10: patched: Initial patch committed to stable tree.

References

Related threats