Impact
In the Linux kernel’s accel/rocket driver, rocket_job_run() mistakenly takes an extra fence reference and increments the runtime PM counter on error without releasing them. This results in a leak of the dma_f that blocks the NVIDIA Processing Unit from suspending, and the return of an unsignaled fence that causes a WARN in the DRM scheduler. The consequence is memory and power‑management resource exhaustion, system instability, and degraded power efficiency.
Affected Systems
All Linux kernel builds that include the accel/rocket driver prior to the upstream commit that replaces pm_runtime_get_sync() with pm_runtime_resume_and_get() are vulnerable. The generic Linux kernel CPE and the “Linux:Linux” CNA vendor list indicate that mainstream distributions shipping a kernel with the buggy driver path are at risk. No specific kernel version numbers are listed, so the impact spans any kernel that retains the unpatched code.
Risk and Exploitability
The CVSS score of 4.7 reflects medium severity, while an EPSS score of < 1% indicates a very low probability of exploitation. Because the flaw is confined to kernel mode and only triggered during error handling in a driver, an attacker must have local privileges or the ability to run code in kernel space to exploit it. Therefore, the likely attack vector is local privilege escalation or kernel exploitation. The vulnerability is not listed in the CISA KEV catalog, and no public exploits are currently known.
OpenCVE Enrichment