CVE-2026-98143
In the Linux kernel, the following vulnerability has been resolved:
accel: ethosu: Don't read the U65 rounding mode as a storage mode
Bits 15:14 of NPU_SET_{IFM,OFM}_PRECISION select the activation storage mode on U85 only. On U65 the same field holds the rounding mode, and the command stream parser has read it as a storage mode since the driver was added.
That went unnoticed while unknown values fell through the switch, but now that they are rejected, every U65 command stream that asks for natural rounding (2) fails CMDSTREAM_BO_CREATE with -EINVAL.
Read full descriptionShow less
Mesa emits it for average pooling, concatenation, split, unpack, strided slice, LUT and argmax, which is 72 failures of the Teflon test suite on an i.MX93. Truncating rounding (1) is misread as well: it picks the two-tile address path and computes a bogus feature map size from tile bases the command stream never set.
Read the field as a storage mode only on the hardware where it is one.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Base score: 7.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.11%
- Percentile among all scored CVEs: 1
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1068Exploitation for Privilege Escalationprivilege escalation75 % - Primary impact
T1499.004Application or System Exploitationimpact65 % - Secondary impact
T1565.001Stored Data Manipulationimpact60 %
Vulnerabilidad local en kernel (AV:L/PR:L) que causa rechazo de comando válido (-EINVAL) y cálculo incorrecto de parámetros, resultando en DoS de funcionalidad (average pooling, LUT, etc.) y posible corrupción de datos de feature map.
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
References
Raw JSON (NVD)
Show
{
"id": "CVE-2026-98143",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5a5e9c0228e613f0ef2a58b9782d7c0ea8f1e58b",
"lessThan": "6b08adbda8ea797849e3654ce12cb3856ce6051a",
"versionType": "git"
},
{
"status": "affected",
"version": "5a5e9c0228e613f0ef2a58b9782d7c0ea8f1e58b",
"lessThan": "db9deec5a345abc538d081fb221dc0b00a9695bd",
"versionType": "git"
}
],
"programFiles": [
"drivers/accel/ethosu/ethosu_gem.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.19"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.19",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/accel/ethosu/ethosu_gem.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:45.830",
"references": [
{
"url": "https://git.kernel.org/stable/c/6b08adbda8ea797849e3654ce12cb3856ce6051a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/db9deec5a345abc538d081fb221dc0b00a9695bd",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Undergoing Analysis",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\naccel: ethosu: Don't read the U65 rounding mode as a storage mode\n\nBits 15:14 of NPU_SET_{IFM,OFM}_PRECISION select the activation storage\nmode on U85 only. On U65 the same field holds the rounding mode, and the\ncommand stream parser has read it as a storage mode since the driver was\nadded.\n\nThat went unnoticed while unknown values fell through the switch, but\nnow that they are rejected, every U65 command stream that asks for\nnatural rounding (2) fails CMDSTREAM_BO_CREATE with -EINVAL. Mesa emits\nit for average pooling, concatenation, split, unpack, strided slice, LUT\nand argmax, which is 72 failures of the Teflon test suite on an i.MX93.\nTruncating rounding (1) is misread as well: it picks the two-tile\naddress path and computes a bogus feature map size from tile bases the\ncommand stream never set.\n\nRead the field as a storage mode only on the hardware where it is one."
}
],
"lastModified": "2026-09-30T14:10:59.253",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}