« Back to list

CVE-2026-97911

Status: ReceivedHigh (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

accel: ethosu: Ensure SRAM region size matches job

It is possible for userspace to set the job SRAM size to 0, but then still have SRAM accesses in the command stream. When the job SRAM size is 0, setting the region base register is skipped and a stale base address from a prior job is used.

Check the region size against the job's SRAM size instead of just the size of the SRAM. The job's SRAM size was already checked against the total SRAM size.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

AV:L/PR:L/UI:N permite escalada local. El acceso a SRAM stale posibilita ejecución o lectura de datos del kernel.

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (1)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2026-97911",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "9cff90774872ed6613b7571ce018b5b455d86890",
              "lessThan": "50c27d412fedc95b8d54d477af47451a382e8cdd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9cff90774872ed6613b7571ce018b5b455d86890",
              "lessThan": "2b39d680c9e0fb4d625f2916980977622e84248c",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/accel/ethosu/ethosu_job.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.2"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.2",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/accel/ethosu/ethosu_job.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:18.070",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2b39d680c9e0fb4d625f2916980977622e84248c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/50c27d412fedc95b8d54d477af47451a382e8cdd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\naccel: ethosu: Ensure SRAM region size matches job\n\nIt is possible for userspace to set the job SRAM size to 0, but then still\nhave SRAM accesses in the command stream. When the job SRAM size is 0,\nsetting the region base register is skipped and a stale base address from\na prior job is used.\n\nCheck the region size against the job's SRAM size instead of just the size\nof the SRAM. The job's SRAM size was already checked against the total SRAM\nsize."
    }
  ],
  "lastModified": "2026-09-25T15:18:02.220",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}