accel/ethosu: fix IFM region index out-of-bounds in command stream parser
Published Jun 25, 2026
7.8
HIGHCVSS 3.1
EPSS 0.12%
Description
NPU_SET_IFM_REGION extracts the region index with param & 0x7f, giving a maximum value of 127. However region_size[] and output_region[] in struct ethosu_validated_cmdstream_info are both sized to NPU_BASEP_REGION_MAX (8), giving valid indices [0..7].
Every other region assignment in the same switch uses param & 0x7: NPU_SET_OFM_REGION: st.ofm.region = param & 0x7; NPU_SET_IFM2_REGION: st.ifm2.region = param & 0x7; NPU_SET_WEIGHT_REGION: st.weight[0].region = param & 0x7; NPU_SET_SCALE_REGION: st.scale[0].region = param & 0x7;
The 0x7f mask on IFM is inconsistent and appears to be a typo.
feat_matrix_length() and calc_sizes() use the region index directly as an array subscript into the kzalloc'd info struct: info->region_size[fm->region] = max(...);
A userspace caller supplying NPU_SET_IFM_REGION with param > 7 causes a write up to 127*8 = 1016 bytes past the start of region_size[], corrupting adjacent kernel heap data.
Fix by applying the same & 0x7 mask used by all other region assignments.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.19StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.19
- Version 7.0.13StatusunaffectedConstraints<=7.0.*
- Version 7.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 6.19 · < 7.0.13
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- https://access.redhat.com/security/cve/CVE-2026-53172 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2492781 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39263 Advisory
- https://git.kernel.org/stable/c/00f547e0dfecf83014fb32bcba587c6b684c1362 Patch
- https://git.kernel.org/stable/c/ee7bed779def61ebff1b92b0e851f412176fa416 Patch
- https://lore.kernel.org/linux-cve-announce/2026062552-CVE-2026-53172-11a3@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-53172
- https://www.cve.org/CVERecord?id=CVE-2026-53172
Change history (0)
No recorded changes yet.