CVE-2026-68316

Summary

In the Linux kernel, the following vulnerability has been resolved:

accel: ethosu: Fix element size accounting for cmd stream validation

There are 2 issues with the element size handling in the command stream validation which result in too small of a size calculated when the element size is 16/32/64 bits.

For NHWC format, the element size is simply missing from the calculation.

The bitfield for the element size is different between IFM/IFM2 and OFM. IFM and IFM2 encode the precision in parameter bits 2:3, while OFM uses bits 1:2.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux5a5e9c0228e613f0ef2a58b9782d7c0ea8f1e58b < b4ae748f8e6cb65bb86e5a281bbb5b5e5f106527affected
LinuxLinux5a5e9c0228e613f0ef2a58b9782d7c0ea8f1e58b < 18a551482a4a326790698b273e76d7575a51a57daffected
LinuxLinux6.19affected
LinuxLinux0 < 6.19unaffected
LinuxLinux7.1.6 <= 7.1.*unaffected
LinuxLinux7.2-rc5 <= *unaffected

Weaknesses

References