🔴 高危 | CVE-2026-53170 — In the Linux kernel, the following vulnerability has be
🔴 《高危安全漏洞:CVE-2026-53170》
CVSS 评分: 高危(8.8) CVE ID: CVE-2026-53170
漏洞描述
In the Linux kernel, the following vulnerability has been resolved:
accel/ethosu: reject DMA commands with uninitialized length
cmd_state_init() initializes the command state with memset(0xff),
leaving dma->len at U64_MAX to signal missing setup. The only setter
is NPU_SET_DMA0_LEN; if userspace omits this command and issues
NPU_OP_DMA_START, dma->len remains U64_MAX.
In dma_length(), a positive stride added to U64_MAX wraps to a small
value. With size0 == 1, check_mul_overflow() does not trigger and
dma_length() returns 0 instead of U64_MAX. The caller's U64_MAX check
then passes, region_size[] stays 0, and the bounds check in
ethosu_job.c is bypassed, allowing hardware to execute DMA with stale
physical addresses.
Fix by checking for U64_MAX at the start of dma_length() before any
arithmetic, consistent with the sentinel value used throughout the
driver to detect uninitialized fields.
| 字段 | 值 |
|---|---|
| CVE ID | CVE-2026-53170 |
| CVSS 评分 | 8.8 |
| 严重程度 | 高危 |
| 发布时间 | 2026-06-25 |
| 状态 | Received |
数据来源: NVD | 获取时间: 2026-06-28 18:14