CVE-2026-53170
published 2026-06-25CVE-2026-53170: In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: reject DMA commands with uninitialized length cmd_state_init() initializes…
PriorityP345high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.14%
3.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
accel/ethosu: reject DMA commands with uninitialized length
cmd_state_init() initializes the command state with memset(0xff),
leaving dma->len at U64_MAX to signal missing setup. The only setter
is NPU_SET_DMA0_LEN; if userspace omits this command and issues
NPU_OP_DMA_START, dma->len remains U64_MAX.
In dma_length(), a positive stride added to U64_MAX wraps to a small
value. With size0 == 1, check_mul_overflow() does not trigger and
dma_length() returns 0 instead of U64_MAX. The caller's U64_MAX check
then passes, region_size[] stays 0, and the bounds check in
ethosu_job.c is bypassed, allowing hardware to execute DMA with stale
physical addresses.
Fix by checking for U64_MAX at the start of dma_length() before any
arithmetic, consistent with the sentinel value used throughout the
driver to detect uninitialized fields.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= 5a5e9c0228e613f0ef2a58b9782d7c0ea8f1e58b < fb25c76a820ca8a547aa478bfb503da0a11494ab | fb25c76a820ca8a547aa478bfb503da0a11494ab |
| linux | linux | >= 5a5e9c0228e613f0ef2a58b9782d7c0ea8f1e58b < d9d021218162b6c4fe0bdf42b2b340f1aae23a12 | d9d021218162b6c4fe0bdf42b2b340f1aae23a12 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 6.19 < 7.0.13 | 7.0.13 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 7.0.12 accel ethosu_job.c cmd_state_init sentinel uninitialized pointer (WID-SEC-2026-2077)
vuldb·2026-06-29·CVSS 8.8
CVE-2026-53170 [HIGH] Linux Kernel up to 7.0.12 accel ethosu_job.c cmd_state_init sentinel uninitialized pointer (WID-SEC-2026-2077)
A vulnerability labeled as critical has been found in Linux Kernel up to 7.0.12. Impacted is the function cmd_state_init of the file ethosu_job.c of the component accel. Such manipulation of the argument sentinel leads to uninitialized pointer.
This vulnerability is documented as CVE-2026-53170. The attack can be executed directly on the physical device. There is not any exploit available.
The affected component should be upgraded.
GHSA
In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: reject DMA commands with uninitialized length cmd_state_init() initializes the command state with memset(0xff), leav
ghsa_unreviewed·2026-06-25
CVE-2026-53170 In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: reject DMA commands with uninitialized length cmd_state_init() initializes the command state with memset(0xff), leav
In the Linux kernel, the following vulnerability has been resolved:
accel/ethosu: reject DMA commands with uninitialized length
cmd_state_init() initializes the command state with memset(0xff),
leaving dma->len at U64_MAX to signal missing setup. The only setter
is NPU_SET_DMA0_LEN; if userspace omits this command and issues
NPU_OP_DMA_START, dma->len remains U64_MAX.
In dma_length(), a positive stride added to U64_MAX wraps to a small
value. With size0 == 1, check_mul_overflow() does not trigger and
dma_length() returns 0 instead of U64_MAX. The caller's U64_MAX check
then passes, region_size[] stays 0, and the bounds check in
ethosu_job.c is bypassed, allowing hardware to execute DMA with stale
physical addresses.
Fix by checking for U64_MAX at the start of dma_length() before any
ar
Red Hat
kernel: accel/ethosu: reject DMA commands with uninitialized length
vendor_redhat·2026-06-25
CVE-2026-53170 CWE-190 kernel: accel/ethosu: reject DMA commands with uninitialized length
kernel: accel/ethosu: reject DMA commands with uninitialized length
In the Linux kernel, the following vulnerability has been resolved:
accel/ethosu: reject DMA commands with uninitialized length
cmd_state_init() initializes the command state with memset(0xff),
leaving dma->len at U64_MAX to signal missing setup. The only setter
is NPU_SET_DMA0_LEN; if userspace omits this command and issues
NPU_OP_DMA_START, dma->len remains U64_MAX.
In dma_length(), a positive stride added to U64_MAX wraps to a small
value. With size0 == 1, check_mul_overflow() does not trigger and
dma_length() returns 0 instead of U64_MAX. The caller's U64_MAX check
then passes, region_size[] stays 0, and the bounds check in
ethosu_job.c is bypassed, allowing hardware to execute DMA with stale
physical addresses.
Fix b
No detection rules found.
No public exploits indexed.
2026-06-25
Published