Description
In the Linux kernel, the following vulnerability has been resolved:

accel/rocket: Fix error path handling in rocket_job_run()

In rocket_job_run(), after taking an extra fence reference for
job->done_fence via dma_fence_get(), the error paths have three bugs:

- The dma_fence reference held by job->done_fence is never released,
causing a reference leak.
- pm_runtime_get_sync() increments the usage counter even on failure,
but the error path does not decrement it, leaking the runtime PM
reference and preventing the NPU from suspending.
- A valid but unsignaled fence is returned to the DRM scheduler,
which triggers WARN("Fence ... released with pending signals!")
when the scheduler drops its reference.

Fix by replacing pm_runtime_get_sync() with pm_runtime_resume_and_get()
which auto-balances the usage counter on failure, releasing both fence
references on error, and returning ERR_PTR(ret) instead of the
unsignaled fence.

[tomeu: Refactored error paths to use consolidated goto labels]
Published: 2026-09-11
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Device suspend failure and resource exhaustion
Action: Apply patch
AI Analysis

Impact

In the Linux kernel’s accel/rocket driver, rocket_job_run() mistakenly takes an extra fence reference and increments the runtime PM counter on error without releasing them. This results in a leak of the dma_f that blocks the NVIDIA Processing Unit from suspending, and the return of an unsignaled fence that causes a WARN in the DRM scheduler. The consequence is memory and power‑management resource exhaustion, system instability, and degraded power efficiency.

Affected Systems

All Linux kernel builds that include the accel/rocket driver prior to the upstream commit that replaces pm_runtime_get_sync() with pm_runtime_resume_and_get() are vulnerable. The generic Linux kernel CPE and the “Linux:Linux” CNA vendor list indicate that mainstream distributions shipping a kernel with the buggy driver path are at risk. No specific kernel version numbers are listed, so the impact spans any kernel that retains the unpatched code.

Risk and Exploitability

The CVSS score of 4.7 reflects medium severity, while an EPSS score of < 1% indicates a very low probability of exploitation. Because the flaw is confined to kernel mode and only triggered during error handling in a driver, an attacker must have local privileges or the ability to run code in kernel space to exploit it. Therefore, the likely attack vector is local privilege escalation or kernel exploitation. The vulnerability is not listed in the CISA KEV catalog, and no public exploits are currently known.

Generated by OpenCVE AI on September 15, 2026 at 21:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official kernel patch from the upstream commit that replaces pm_runtime_get_sync() with pm_runtime_resume_and_get()
  • If the vendor’s distribution cannot your existing kernel source, rebuild, and reboot to load the corrected driver
  • As a temporary mitigation, unload or disable the accel/rocket kernel module until a kernel version with the fix is available

Generated by OpenCVE AI on September 15, 2026 at 21:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-911
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: accel/rocket: Fix error path handling in rocket_job_run() In rocket_job_run(), after taking an extra fence reference for job->done_fence via dma_fence_get(), the error paths have three bugs: - The dma_fence reference held by job->done_fence is never released, causing a reference leak. - pm_runtime_get_sync() increments the usage counter even on failure, but the error path does not decrement it, leaking the runtime PM reference and preventing the NPU from suspending. - A valid but unsignaled fence is returned to the DRM scheduler, which triggers WARN("Fence ... released with pending signals!") when the scheduler drops its reference. Fix by replacing pm_runtime_get_sync() with pm_runtime_resume_and_get() which auto-balances the usage counter on failure, releasing both fence references on error, and returning ERR_PTR(ret) instead of the unsignaled fence. [tomeu: Refactored error paths to use consolidated goto labels]
Title accel/rocket: Fix error path handling in rocket_job_run()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:44:54.328Z

Reserved: 2026-09-11T19:38:34.730Z

Link: CVE-2026-89590

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:43.567

Modified: 2026-09-11T20:19:43.567

Link: CVE-2026-89590

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:54Z

Links: CVE-2026-89590 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:00:17Z

Weaknesses
  • CWE-911

    Improper Update of Reference Count