In the Linux kernel, the following vulnerability has been resolved: accel/rocket: Fix error path handling in rocket_job_run() In rocket_job_run(),… (CVE-2026-89590)
A vulnerability in the Linux kernel's accel/rocket component was fixed by correcting error path handling in the rocket_job_run() function. The issue involved three bugs related to reference management: a dma_fence reference leak, a runtime PM usage counter leak preventing NPU suspension, and returning a valid but unsignaled fence causing warnings in the DRM scheduler. The fix replaced pm_runtime_get_sync() with pm_runtime_resume_and_get() to properly balance usage counters and release references on error.
AI Analysis
Technical Summary
The Linux kernel vulnerability CVE-2026-89590 concerns the accel/rocket driver, specifically the rocket_job_run() function. The function improperly handled error paths after taking an extra fence reference via dma_fence_get(), leading to three bugs: a leaked dma_fence reference, a leaked runtime PM reference due to improper usage counter decrementing, and returning an unsignaled fence to the DRM scheduler which triggers warnings. The fix involved replacing pm_runtime_get_sync() with pm_runtime_resume_and_get(), which correctly manages usage counters and releases references on failure, preventing leaks and scheduler warnings.
Potential Impact
The vulnerability causes resource leaks including dma_fence references and runtime PM usage counters, which can prevent the NPU from suspending properly and trigger warnings in the DRM scheduler. These issues may degrade system stability or performance but no direct exploitation or active attacks are reported.
Mitigation Recommendations
A fix is available and has been applied in the Linux kernel by replacing pm_runtime_get_sync() with pm_runtime_resume_and_get() in rocket_job_run(). Users should update to the fixed kernel version containing this patch. No additional mitigation steps are indicated.
In the Linux kernel, the following vulnerability has been resolved: accel/rocket: Fix error path handling in rocket_job_run() In rocket_job_run(),… (CVE-2026-89590)
Description
A vulnerability in the Linux kernel's accel/rocket component was fixed by correcting error path handling in the rocket_job_run() function. The issue involved three bugs related to reference management: a dma_fence reference leak, a runtime PM usage counter leak preventing NPU suspension, and returning a valid but unsignaled fence causing warnings in the DRM scheduler. The fix replaced pm_runtime_get_sync() with pm_runtime_resume_and_get() to properly balance usage counters and release references on error.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel vulnerability CVE-2026-89590 concerns the accel/rocket driver, specifically the rocket_job_run() function. The function improperly handled error paths after taking an extra fence reference via dma_fence_get(), leading to three bugs: a leaked dma_fence reference, a leaked runtime PM reference due to improper usage counter decrementing, and returning an unsignaled fence to the DRM scheduler which triggers warnings. The fix involved replacing pm_runtime_get_sync() with pm_runtime_resume_and_get(), which correctly manages usage counters and releases references on failure, preventing leaks and scheduler warnings.
Potential Impact
The vulnerability causes resource leaks including dma_fence references and runtime PM usage counters, which can prevent the NPU from suspending properly and trigger warnings in the DRM scheduler. These issues may degrade system stability or performance but no direct exploitation or active attacks are reported.
Mitigation Recommendations
A fix is available and has been applied in the Linux kernel by replacing pm_runtime_get_sync() with pm_runtime_resume_and_get() in rocket_job_run(). Users should update to the fixed kernel version containing this patch. No additional mitigation steps are indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-8m8f-887v-xxcc
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-89590"]
Threat ID: 6aa4a00d55bf5e2cf5a86687
Added to database: 09/12/2026, 00:42:53 UTC
Last enriched: 09/12/2026, 01:03:57 UTC
Last updated: 09/12/2026, 01:03:57 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.