NULL pointer dereference in Linux kernel - CVE-2026-89592
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a kernel null pointer dereference.
The vulnerability exists due to a missing null pointer check in rocket_job_push() when allocating a temporary GEM object pointer array. A local user can submit a job with input and output GEM object handles to cause a kernel null pointer dereference.
Exploitation requires the temporary array allocation to fail.