๐Ÿ” CVE Alert

CVE-2026-97916

UNKNOWN 0.0

accel/ivpu: Validate firmware log buffer metadata

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Validate firmware log buffer metadata The tracing log headers parsed by fw_log_print_buffer() reside in DMA-shared BOs that the NPU firmware can write to. fw_log_from_bo() validated log->header_size and log->size, but fw_log_print_buffer() re-read those same fields from shared memory afterwards, allowing a TOCTOU where firmware changes them between the check and the use, and making the host dereference out-of-bounds addresses while printing logs. Snapshot the validated values once with READ_ONCE() and pass them down explicitly in a new struct ivpu_fw_log_desc instead of re-reading them from the shared struct.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
d4e4257afa6ed5205eda993180401fc2c20e4b60 < 8ec3d6972f1440fae6c8dadd1859892775208759 d4e4257afa6ed5205eda993180401fc2c20e4b60 < 40868f80a89199630b03d4457876f9a1feba0660 d4e4257afa6ed5205eda993180401fc2c20e4b60 < b1555f63ee1a680f280bc18e8dac416f250e2ec3 d4e4257afa6ed5205eda993180401fc2c20e4b60 < 0724afc55c77c36c7feb9a7264b02aa7593c5c2d
Linux / Linux
6.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/8ec3d6972f1440fae6c8dadd1859892775208759 git.kernel.org: https://git.kernel.org/stable/c/40868f80a89199630b03d4457876f9a1feba0660 git.kernel.org: https://git.kernel.org/stable/c/b1555f63ee1a680f280bc18e8dac416f250e2ec3 git.kernel.org: https://git.kernel.org/stable/c/0724afc55c77c36c7feb9a7264b02aa7593c5c2d