{"id":"CVE-2026-89590","title":"kernel: accel/rocket: Fix error path handling in rocket_job_run() (CVE-2026-89590)","summary":"A flaw was found in the `accel/rocket` driver within the Linux kernel. Incorrect error handling in the `rocket_job_run()` function can lead to resource leaks. This occurs when the system fails to properly release references to Direct Memor…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-911","vendor":"Red Hat","product":"Linux","affected":["Linux >= 0810d5ad88a18f1e6d549853a388ad0316f74e36 < 9ad8821573a36bcd18c84dbca3027802b0ea062f","Linux >= 0810d5ad88a18f1e6d549853a388ad0316f74e36 < 7d6fa298c23495b805004f5f446497b661998fa5","Linux >= 0810d5ad88a18f1e6d549853a388ad0316f74e36 < 9b2dedadf6a91ac3fc9fae268bb556a041222711","Linux 6.18"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T09:12:19+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89590.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89590.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89590"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532024"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89590"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89590"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89590.mbox"},{"url":"https://git.kernel.org/stable/c/9ad8821573a36bcd18c84dbca3027802b0ea062f"},{"url":"https://git.kernel.org/stable/c/7d6fa298c23495b805004f5f446497b661998fa5"},{"url":"https://git.kernel.org/stable/c/9b2dedadf6a91ac3fc9fae268bb556a041222711"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00166,"epssPercentile":0.06248,"ingestedAt":"2026-09-14T11:11:19.886Z","slug":"CVE-2026-89590","body":"## Overview\n\nA flaw was found in the `accel/rocket` driver within the Linux kernel. Incorrect error handling in the `rocket_job_run()` function can lead to resource leaks. This occurs when the system fails to properly release references to Direct Memory Access (DMA) fences and Power Management (PM) resources during error conditions. The consequence is that the Neural Processing Unit (NPU) may be prevented from suspending, leading to resource exhaustion and potential system instability.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89590.json)\n\n**kernel: accel/rocket: Fix error path handling in rocket_job_run()** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nRefer to the advisory for fix availability.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":202798,"id":"CVE-2026-89590","ts":1789403723180,"field":"cvss","old":null,"new":"5.5"},{"seq":202797,"id":"CVE-2026-89590","ts":1789403723180,"field":"severity","old":"none","new":"medium"},{"seq":109610,"id":"CVE-2026-89590","ts":1789183732611,"field":"cvss","old":null,"new":"4.7"},{"seq":109609,"id":"CVE-2026-89590","ts":1789183732611,"field":"severity","old":"none","new":"medium"}]}