CVE-2026-53172
Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-125
Lectura fuera de límites
Fecha de publicación:
25/06/2026
Última modificación:
06/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
accel/ethosu: fix IFM region index out-of-bounds in command stream parser<br />
<br />
NPU_SET_IFM_REGION extracts the region index with param & 0x7f, giving<br />
a maximum value of 127. However region_size[] and output_region[] in<br />
struct ethosu_validated_cmdstream_info are both sized to<br />
NPU_BASEP_REGION_MAX (8), giving valid indices [0..7].<br />
<br />
Every other region assignment in the same switch uses param & 0x7:<br />
NPU_SET_OFM_REGION: st.ofm.region = param & 0x7;<br />
NPU_SET_IFM2_REGION: st.ifm2.region = param & 0x7;<br />
NPU_SET_WEIGHT_REGION: st.weight[0].region = param & 0x7;<br />
NPU_SET_SCALE_REGION: st.scale[0].region = param & 0x7;<br />
<br />
The 0x7f mask on IFM is inconsistent and appears to be a typo.<br />
<br />
feat_matrix_length() and calc_sizes() use the region index directly<br />
as an array subscript into the kzalloc&#39;d info struct:<br />
info->region_size[fm->region] = max(...);<br />
<br />
A userspace caller supplying NPU_SET_IFM_REGION with param > 7 causes<br />
a write up to 127*8 = 1016 bytes past the start of region_size[],<br />
corrupting adjacent kernel heap data.<br />
<br />
Fix by applying the same & 0x7 mask used by all other region<br />
assignments.
Impacto
Puntuación base 3.x
7.80
Gravedad 3.x
ALTA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (incluyendo) | 7.0.13 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página



