---
id: CVE-2026-64008
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  accel/rocket: fix UAF via dangling GEM handle in create_bo

  rocket_ioctl_create_bo() inserts a GEM handle into the file's IDR via
  drm_gem_handle_create() early on, then…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  accel/rocket: fix UAF via dangling GEM handle in create_bo

  rocket_ioctl_create_bo() inserts a GEM handle into the file's IDR via
  drm_gem_handle_create() early on, then…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-416
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 6.18, < 6.18.35'
  - 'linux_kernel >= 6.19, < 7.0.12'
  - linux_kernel = 7.1
patched:
  - linux_kernel 7.0.12
published: '2026-07-19'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T19:55:18.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-64008'
references:
  - url: 'https://git.kernel.org/stable/c/18abd88d19ea195e2e1547fca0970c2f91d77a42'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/451f1ccbbdb7b65021646704b15902655f8d228a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f706e6a4ce75585af979aec3dcbdce68bc76306b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00173
epssPercentile: 0.06086
ingestedAt: '2026-10-02T22:33:09.810Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

accel/rocket: fix UAF via dangling GEM handle in create_bo

rocket_ioctl_create_bo() inserts a GEM handle into the file's IDR via
drm_gem_handle_create() early on, then performs several operations that
can fail (sgt allocation, drm_mm insert, iommu_map). If any fail after
the handle is live, the error path calls drm_gem_shmem_object_free()
which kfree's the object without removing the handle from the IDR.

This leaves a dangling handle pointing to freed slab memory. Any
subsequent ioctl using that handle (PREP_BO, FINI_BO, SUBMIT) calls
drm_gem_object_lookup() and dereferences freed memory (UAF).

Fix by moving drm_gem_handle_create() to after all fallible operations
succeed, matching the pattern used by panfrost, lima, and etnaviv.

Also fix drm_mm_insert_node_generic() whose return value was silently
overwritten by iommu_map_sgtable() on the next line. Add the missing
error check.

[tomeu: Move handle creation to the very end]

## Affected

- `linux_kernel >= 6.18, < 6.18.35`
- `linux_kernel >= 6.19, < 7.0.12`
- `linux_kernel = 7.1`

## Remediation

Upgrade past the affected range:

- `linux_kernel 7.0.12`
