CVE-2026-68316: accel: ethosu: Fix element size accounting for cmd stream validation
In the Linux kernel, the following vulnerability has been resolved:
accel: ethosu: Fix element size accounting for cmd stream validation
There are 2 issues with the element size handling in the command stream validation which result in too small of a size calculated when the element size is 16/32/64 bits.
For NHWC format, the element size is simply missing from the calculation.
The bitfield for the element size is different between IFM/IFM2 and OFM. IFM and IFM2 encode the precision in parameter bits 2:3, while OFM uses bits 1:2.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68316?
CVE-2026-68316 has a risk score of 37.
How do I fix CVE-2026-68316?
To fix CVE-2026-68316, update your Linux kernel to the latest patched version available.
What systems are affected by CVE-2026-68316?
CVE-2026-68316 affects Linux kernel implementations that utilize the ethosu command stream validation.
What are the potential impacts of CVE-2026-68316?
The potential impacts of CVE-2026-68316 include incorrect element size calculations that could lead to vulnerabilities in command stream processing.
When was CVE-2026-68316 published?
CVE-2026-68316 was published on August 10, 2026.