CVE-2026-89590

Summary

In the Linux kernel, the following vulnerability has been resolved:

accel/rocket: Fix error path handling in rocket_job_run()

In rocket_job_run(), after taking an extra fence reference for job->done_fence via dma_fence_get(), the error paths have three bugs:

  • The dma_fence reference held by job->done_fence is never released, causing a reference leak.
  • pm_runtime_get_sync() increments the usage counter even on failure, but the error path does not decrement it, leaking the runtime PM reference and preventing the NPU from suspending.
  • A valid but unsignaled fence is returned to the DRM scheduler, which triggers WARN("Fence … released with pending signals!") when the scheduler drops its reference.

Fix by replacing pm_runtime_get_sync() with pm_runtime_resume_and_get() which auto-balances the usage counter on failure, releasing both fence references on error, and returning ERR_PTR(ret) instead of the unsignaled fence.

[tomeu: Refactored error paths to use consolidated goto labels]

Affected Software

VendorProductVersion RangeStatus
LinuxLinux0810d5ad88a18f1e6d549853a388ad0316f74e36 < 9ad8821573a36bcd18c84dbca3027802b0ea062faffected
LinuxLinux0810d5ad88a18f1e6d549853a388ad0316f74e36 < 7d6fa298c23495b805004f5f446497b661998fa5affected
LinuxLinux0810d5ad88a18f1e6d549853a388ad0316f74e36 < 9b2dedadf6a91ac3fc9fae268bb556a041222711affected
LinuxLinux6.18affected
LinuxLinux0 < 6.18unaffected
LinuxLinux6.18.50 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References