CVE-2026-53170
Last modified
CVE-2026-53170 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: reject DMA commands with uninitialized length cmd_state_init() initializes the command state with memset(0xff), leaving dma->len at U64_MAX to signal missing setup. The only setter is NPU_SET_DMA0_LEN; if userspace omits this command and issues NPU_OP_DMA_START, dma->len remains U64_MAX. In dma_length(), a positive stride added to U64_MAX wraps to a small value. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: reject DMA commands with uninitialized length cmd_state_init() initializes the command state with memset(0xff), leaving dma->len at U64_MAX to signal missing setup. The only setter is NPU_SET_DMA0_LEN; if userspace omits this command and issues NPU_OP_DMA_START, dma->len remains U64_MAX. In dma_length(), a positive stride added to U64_MAX wraps to a small value. With size0 == 1, check_mul_overflow() does not trigger and dma_length() returns 0 instead of U64_MAX. The caller's U64_MAX check then passes, region_size[] stays 0, and the bounds check in ethosu_job.c is bypassed, allowing hardware to execute DMA with stale physical addresses. Fix by checking for U64_MAX at the start of dma_length() before any arithmetic, consistent with the sentinel value used throughout the driver to detect uninitialized fields.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Linux | Linux Kernel | >= 6.19, < 7.0.13 | — |
| Linux | Linux Kernel | 7.1 | Rc1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-53170?
How severe is CVE-2026-53170?
How do I fix CVE-2026-53170?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-53165In the Linux kernel, the following vulnerability has been re…7.5
- CVE-2026-53166Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-53167In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-53168In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-53169In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-5317A security flaw has been discovered in Nothings stb up to 1.…8.8
- CVE-2026-53171In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-53172In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-53173In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-53174In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-53175In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-53176In the Linux kernel, the following vulnerability has been re…9.8
Are you affected by CVE-2026-53170?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
