CVE-2026-53172
Severity CVSS v4.0:
Pending analysis
Type:
CWE-125
Out-of-bounds Read
Publication date:
25/06/2026
Last modified:
06/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
accel/ethosu: fix IFM region index out-of-bounds in command stream parser<br />
<br />
NPU_SET_IFM_REGION extracts the region index with param & 0x7f, giving<br />
a maximum value of 127. However region_size[] and output_region[] in<br />
struct ethosu_validated_cmdstream_info are both sized to<br />
NPU_BASEP_REGION_MAX (8), giving valid indices [0..7].<br />
<br />
Every other region assignment in the same switch uses param & 0x7:<br />
NPU_SET_OFM_REGION: st.ofm.region = param & 0x7;<br />
NPU_SET_IFM2_REGION: st.ifm2.region = param & 0x7;<br />
NPU_SET_WEIGHT_REGION: st.weight[0].region = param & 0x7;<br />
NPU_SET_SCALE_REGION: st.scale[0].region = param & 0x7;<br />
<br />
The 0x7f mask on IFM is inconsistent and appears to be a typo.<br />
<br />
feat_matrix_length() and calc_sizes() use the region index directly<br />
as an array subscript into the kzalloc&#39;d info struct:<br />
info->region_size[fm->region] = max(...);<br />
<br />
A userspace caller supplying NPU_SET_IFM_REGION with param > 7 causes<br />
a write up to 127*8 = 1016 bytes past the start of region_size[],<br />
corrupting adjacent kernel heap data.<br />
<br />
Fix by applying the same & 0x7 mask used by all other region<br />
assignments.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 7.0.13 (excluding) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



