Description
In the Linux kernel, the following vulnerability has been resolved:

accel/rocket: initialize job domain before cleanup paths

rocket_ioctl_submit_job() releases rjob through rocket_job_put() on
allocation error paths. rocket_job_cleanup() unconditionally calls
rocket_iommu_domain_put(job->domain), but job->domain is assigned only
after task copying and BO lookups. A failure before that assignment can
therefore clean up a job with a NULL domain pointer.

Take the per-file domain reference before the first error path can release
rjob. Also clear rjob->tasks after freeing it in rocket_copy_tasks(), so
the common cleanup path cannot free the task array again after a task-copy
error.
Published: 2026-09-11
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

During an error that occurs before the accel/rocket task domain is assigned, the driver’s cleanup routine calls the kernel function to release the domain pointer. Because that pointer is null at that time, the call dereferences a null pointer in kernel space, causing the operating system to crash. The crash results in a blanket denial of service for the entire host, as normal kernel operation cannot continue.

Affected Systems

Linux kernel ships containing the accel/rocket driver before the commit that initializes the job domain before cleanup are vulnerable. All distributions and custom kernel builds that have not yet incorporated this patch, or that still use the older driver code, fall into this category.

Risk and Exploitability

The CVSS score of 5.5 classifies this flaw as moderate severity, while the EPSS score of <1% suggests a very low chance of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploits. Based on the description, it is inferred that an attacker would need local access to the accel/rocket device’s ioctl interface and be able to provoke the error that triggers the null dereference in the cleanup path.

Generated by OpenCVE AI on September 15, 2026 at 22:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a release that includes the commit which initializes the job domain before cleanup.
  • If an immediate kernel upgrade is not feasible, cherry‑pick or apply the specific commit to the current source tree, recompile the kernel, and reboot into the patched image.
  • Restrict the device file exposed by the accel/rocket driver to trusted, privileged users only, limiting the number of processes that can invoke the problematic ioctl path.

Generated by OpenCVE AI on September 15, 2026 at 22:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: accel/rocket: initialize job domain before cleanup paths rocket_ioctl_submit_job() releases rjob through rocket_job_put() on allocation error paths. rocket_job_cleanup() unconditionally calls rocket_iommu_domain_put(job->domain), but job->domain is assigned only after task copying and BO lookups. A failure before that assignment can therefore clean up a job with a NULL domain pointer. Take the per-file domain reference before the first error path can release rjob. Also clear rjob->tasks after freeing it in rocket_copy_tasks(), so the common cleanup path cannot free the task array again after a task-copy error.
Title accel/rocket: initialize job domain before cleanup paths
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:44:55.080Z

Reserved: 2026-09-11T19:38:34.730Z

Link: CVE-2026-89591

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:43.683

Modified: 2026-09-11T20:19:43.683

Link: CVE-2026-89591

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:55Z

Links: CVE-2026-89591 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:15:17Z

Weaknesses