---
cve: "CVE-2026-89590"
severity: "LOW"
cvss: 3.1
epss: "0.2%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-09-11 20:19:43"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-21T10:57:04+02:00"
---

# CVE-2026-89590

> 3.1 LOW

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

accel/rocket: Fix error path handling in rocket_job_run()

In rocket_job_run(), after taking an extra fence reference for
job->done_fence via dma_fence_get(), the error paths have three bugs:

- The dma_fence reference held by job->done_fence is never released,
  causing a reference leak.
- pm_runtime_get_sync() increments the usage counter even on failure,
  but the error path does not decrement it, leaking the runtime PM
  reference and preventing the NPU from suspending.
- A valid but unsignaled fence is returned to the DRM scheduler,
  which triggers WARN("Fence ... released with pending signals!")
  when the scheduler drops its reference.

Fix by replacing pm_runtime_get_sync() with pm_runtime_resume_and_get()
which auto-balances the usage counter on failure, releasing both fence
references on error, and returning ERR_PTR(ret) instead of the
unsignaled fence.

[tomeu: Refactored error paths to use consolidated goto labels]

## Patch verfügbar (OSV)

- Kernel ≥ 6.18.50
- Kernel ≥ 7.2.4

## Referenzen

- <https://git.kernel.org/stable/c/9ad8821573a36bcd18c84dbca3027802b0ea062f>
- <https://git.kernel.org/stable/c/7d6fa298c23495b805004f5f446497b661998fa5>
- <https://git.kernel.org/stable/c/9b2dedadf6a91ac3fc9fae268bb556a041222711>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-89590) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
