CVE-2026-53170: accel/ethosu: reject DMA commands with uninitialized length
In the Linux kernel, the following vulnerability has been resolved:
accel/ethosu: reject DMA commands with uninitialized length
cmdstateinit() initializes the command state with memset(0xff), leaving dma->len at U64MAX to signal missing setup. The only setter is NPUSETDMA0LEN; if userspace omits this command and issues NPUOPDMASTART, dma->len remains U64MAX.
In dmalength(), a positive stride added to U64MAX wraps to a small value. With size0 == 1, checkmuloverflow() does not trigger and dmalength() returns 0 instead of U64MAX. The caller's U64MAX check then passes, regionsize[] stays 0, and the bounds check in ethosujob.c is bypassed, allowing hardware to execute DMA with stale physical addresses.
Fix by checking for U64MAX at the start of dmalength() before any arithmetic, consistent with the sentinel value used throughout the driver to detect uninitialized fields.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Modify the accel/ethosu driver to reject DMA commands when the DMA length is uninitialized (i.e., when dma->len remains the sentinel value U64_MAX set via cmd_state_init() with memset(0xff)).
accelerator driver: accel/ethosu reject DMA commands with uninitialized length = enabled
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53170?
CVE-2026-53170 has a risk rating of 60, indicating a moderate severity level.
How do I fix CVE-2026-53170?
To mitigate CVE-2026-53170, update the Linux kernel to the latest version that resolves the issue.
What systems are affected by CVE-2026-53170?
CVE-2026-53170 affects systems running the Linux kernel with the accel/ethosu driver.
What is the nature of the vulnerability in CVE-2026-53170?
CVE-2026-53170 involves rejecting DMA commands that have an uninitialized length, which can lead to unintended behavior.
Is there a patch available for CVE-2026-53170?
Yes, a patch for CVE-2026-53170 is included in the latest Linux kernel updates.