VYPR
High severity8.8NVD Advisory· Published Jun 25, 2026· Updated Jul 6, 2026

CVE-2026-53171

CVE-2026-53171

Description

In the Linux kernel, the following vulnerability has been resolved:

accel/ethosu: fix arithmetic issues in dma_length()

dma_length() derives DMA region usage from command stream values and updates region_size[]:

len = ((len + stride[0]) * size0 + stride[1]) * size1 region_size[region] = max(..., len + dma->offset)

Several arithmetic issues can corrupt the derived region size:

  • signed stride values may underflow when added to len
  • intermediate multiplications may overflow
  • len + dma->offset may overflow during region_size updates
  • dma_length() error returns were not validated by the caller

region_size[] is later used by ethosu_job.c to validate command stream accesses against GEM buffer sizes. Arithmetic wraparound can therefore under-report region usage and bypass the bounds validation.

Fix by validating signed additions, using overflow helpers for multiplications and offset updates, and propagating dma_length() failures to the caller.

Affected products

9
  • Linux/Kernelllm-fuzzy8 versions
    (expand)+ 7 more
    • (no CPE)
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=6.19,<7.0.13
    • cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*
  • osv-coords
    Range: >= 6.19.0, < 7.0.13

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.