CVE-2026-53173
published 2026-06-25CVE-2026-53173: In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: fix OOB write in ethosu_gem_cmdstream_copy_and_validate() The command stream…
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
accel/ethosu: fix OOB write in ethosu_gem_cmdstream_copy_and_validate()
The command stream parsing loop increments the index variable a second
time when a 64-bit command word is encountered (bit 14 set), but does
not re-check the loop bound before writing the second word:
for (i = 0; i < size / 4; i++) {
bocmds[i] = cmds[0];
if (cmd & 0x4000) {
i++;
bocmds[i] = cmds[1]; /* unchecked */
}
}
The buffer bocmds is backed by a DMA allocation of exactly size bytes
from drm_gem_dma_create(ddev, size), giving valid indices [0, size/4-1].
When i == size/4 - 1 on entry to an iteration and bit 14 of cmds[0] is
set, bocmds[size/4-1] is written in bounds, i is then incremented to
size/4, and bocmds[size/4] writes four bytes past the end of the
allocation.
Userspace controls both the buffer contents and the size argument via
the ioctl, making this a userspace-triggerable heap out-of-bounds write.
Fix by checking the incremented index against the buffer bound before
the second write and returning -EINVAL if the buffer is too small to
contain the extended command.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= 5a5e9c0228e613f0ef2a58b9782d7c0ea8f1e58b < db6cb3e35cebf487f9a78ebd4cfa4b83708ff40d | db6cb3e35cebf487f9a78ebd4cfa4b83708ff40d |
| linux | linux | >= 5a5e9c0228e613f0ef2a58b9782d7c0ea8f1e58b < c0837b9cf6eabbad8b8cbddaff1a46a6d0a2e29d | c0837b9cf6eabbad8b8cbddaff1a46a6d0a2e29d |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 6.19 < 7.0.13 | 7.0.13 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 7.0.12 accel ethosu_gem_cmdstream_copy_and_validate size out-of-bounds write (WID-SEC-2026-2077)
vuldb·2026-06-29·CVSS 7.8
CVE-2026-53173 [HIGH] Linux Kernel up to 7.0.12 accel ethosu_gem_cmdstream_copy_and_validate size out-of-bounds write (WID-SEC-2026-2077)
A vulnerability classified as critical has been found in Linux Kernel up to 7.0.12. The impacted element is the function ethosu_gem_cmdstream_copy_and_validate of the component accel. Performing a manipulation of the argument size results in out-of-bounds write.
This vulnerability was named CVE-2026-53173. The attack needs to be approached within the local network. There is no available exploit.
It is recommended to upgrade the affected component.
GHSA
In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: fix OOB write in ethosu_gem_cmdstream_copy_and_validate() The command stream parsing loop increments the index varia
ghsa_unreviewed·2026-06-25
CVE-2026-53173 In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: fix OOB write in ethosu_gem_cmdstream_copy_and_validate() The command stream parsing loop increments the index varia
In the Linux kernel, the following vulnerability has been resolved:
accel/ethosu: fix OOB write in ethosu_gem_cmdstream_copy_and_validate()
The command stream parsing loop increments the index variable a second
time when a 64-bit command word is encountered (bit 14 set), but does
not re-check the loop bound before writing the second word:
for (i = 0; i < size / 4; i++) {
bocmds[i] = cmds[0];
if (cmd & 0x4000) {
i++;
bocmds[i] = cmds[1]; /* unchecked */
}
}
The buffer bocmds is backed by a DMA allocation of exactly size bytes
from drm_gem_dma_create(ddev, size), giving valid indices [0, size/4-1].
When i == size/4 - 1 on entry to an iteration and bit 14 of cmds[0] is
set, bocmds[size/4-1] is written in bounds, i is then incremented to
size/4, and bocmds[size/4] writes four bytes past t
Red Hat
kernel: accel/ethosu: fix OOB write in ethosu_gem_cmdstream_copy_and_validate()
vendor_redhat·2026-06-25
CVE-2026-53173 CWE-787 kernel: accel/ethosu: fix OOB write in ethosu_gem_cmdstream_copy_and_validate()
kernel: accel/ethosu: fix OOB write in ethosu_gem_cmdstream_copy_and_validate()
A flaw was found in the Linux kernel's `accel/ethosu` component. A local user can exploit this vulnerability by providing a specially crafted command stream, which causes an out-of-bounds write in memory. This memory corruption can lead to system instability, causing a denial of service or potentially allowing for further unauthorized operations.
Package: kernel (Red Hat Enterprise Linux 10) - Fix deferred
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affect
No detection rules found.
No public exploits indexed.
2026-06-25
Published