« Volver al listado

CVE-2026-89592

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

accel/rocket: fix NULL dereference and integer overflow in rocket_job_push()

rocket_job_push() allocates a temporary array to hold all input and output GEM object pointers:

Two bugs exist:

Fix by using check_add_overflow() to detect count overflow before the allocation, and adding a NULL check on the allocation result.

Detalles técnicos trazas, registros y código del informe original
    bos = kvmalloc_array(job->in_bo_count + job->out_bo_count,
                         sizeof(void *), GFP_KERNEL);
    memcpy(bos, job->in_bos, job->in_bo_count * sizeof(void *));
    memcpy(&bos[job->in_bo_count], job->out_bos, ...);

1. Missing NULL check: if kvmalloc_array() fails, bos is NULL and
   the subsequent memcpy() dereferences it, causing a kernel NULL
   pointer dereference.

2. Integer overflow: in_bo_count and out_bo_count are both u32, set
   directly from userspace-supplied in_bo_handle_count and
   out_bo_handle_count with no prior validation. Their sum is computed
   in u32 arithmetic and can wrap to a smaller value, causing the
   allocation count passed to kvmalloc_array() to be smaller than
   intended. Subsequent uses still operate on the original counts when
   copying and locking objects, which may lead to out-of-bounds accesses
   on the temporary array.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89592",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "0810d5ad88a18f1e6d549853a388ad0316f74e36",
              "lessThan": "c1a5bf1b6e1d5944183dcef3844a18c17219af4d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0810d5ad88a18f1e6d549853a388ad0316f74e36",
              "lessThan": "dfff90a6eb2258e3b867994ae17af4a7ba3504d2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0810d5ad88a18f1e6d549853a388ad0316f74e36",
              "lessThan": "a85402bff218f2b8f0d806e46c16c2f3d49cdda7",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/accel/rocket/rocket_job.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.18"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.18",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.50",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/accel/rocket/rocket_job.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:19:43.807",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/a85402bff218f2b8f0d806e46c16c2f3d49cdda7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c1a5bf1b6e1d5944183dcef3844a18c17219af4d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dfff90a6eb2258e3b867994ae17af4a7ba3504d2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\naccel/rocket: fix NULL dereference and integer overflow in rocket_job_push()\n\nrocket_job_push() allocates a temporary array to hold all input and\noutput GEM object pointers:\n\n    bos = kvmalloc_array(job->in_bo_count + job->out_bo_count,\n                         sizeof(void *), GFP_KERNEL);\n    memcpy(bos, job->in_bos, job->in_bo_count * sizeof(void *));\n    memcpy(&bos[job->in_bo_count], job->out_bos, ...);\n\nTwo bugs exist:\n\n1. Missing NULL check: if kvmalloc_array() fails, bos is NULL and\n   the subsequent memcpy() dereferences it, causing a kernel NULL\n   pointer dereference.\n\n2. Integer overflow: in_bo_count and out_bo_count are both u32, set\n   directly from userspace-supplied in_bo_handle_count and\n   out_bo_handle_count with no prior validation. Their sum is computed\n   in u32 arithmetic and can wrap to a smaller value, causing the\n   allocation count passed to kvmalloc_array() to be smaller than\n   intended. Subsequent uses still operate on the original counts when\n   copying and locking objects, which may lead to out-of-bounds accesses\n   on the temporary array.\n\nFix by using check_add_overflow() to detect count overflow before the\nallocation, and adding a NULL check on the allocation result."
    }
  ],
  "lastModified": "2026-09-11T20:19:43.807",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}