Junglewise Threat Intelligence

CVE-2026-89590: Linux kernel accel/rocket error handling in rocket_job_run()

CVE-2026-89590 · Severity: info · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Rocket accelerator driver contains bugs in error handling for GPU job submissions. When job submission fails, the driver leaks references to fencing objects and runtime power management resources, preventing the NPU from entering low-power states and triggering kernel warnings. This can lead to degraded system performance and resource exhaustion over time.

Technical details

The vulnerability exists in the rocket_job_run() function in drivers/accel/rocket/rocket_job.c. After incrementing a reference count on a DMA fence via dma_fence_get(), error paths in the function fail to properly release resources: (1) the fence reference is never freed on error, (2) pm_runtime_get_sync() increments a usage counter even on failure, but error paths do not decrement it with pm_runtime_put(), and (3) an unsignaled fence is returned to the DRM scheduler triggering a kernel warning. The fix replaces pm_runtime_get_sync() with pm_runtime_resume_and_get() for automatic counter balancing and adds proper error cleanup labels to release both fence references and runtime PM resources before returning an error pointer (ERR_PTR).

Affected products

  • Linux Linux kernel affected versions include at least Linux 6.x and 7.x branches

Timeline

  • 2026-09-11: disclosed
  • 2026-09-07: patched: Fix committed by Greg Kroah-Hartman

References

Related threats