AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-68316

HIGH · CVSS 7.8 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's command stream validation for the ethosu accelerator, where improper element size accounting can lead to incorrect size calculations for 16/32/64-bit elements. This flaw may result in potential data corruption or unexpected behavior during command execution. Organizations utilizing Linux systems with the ethosu accelerator should prioritize addressing this issue to mitigate risks associated with command stream processing.

CVE
CVE-2026-68316
Severity
HIGH
CVSS
7.8
EPSS
0.12%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: accel: ethosu: Fix element size accounting for cmd stream validation There are 2 issues with the element size handling in the command stream validation which result in too small of a size calculated when the element size is 16/32/64 bits. For NHWC format, the element size is simply missing from the calculation. The bitfield for the element size is different between IFM/IFM2 and OFM. IFM and IFM2 encode the precision in parameter bits 2:3, while OFM uses bits 1:2.