OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-97911

HIGH · CVSS 7.8 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of SRAM region sizes in the ethosu accelerator, allowing userspace to set the job SRAM size to zero while still performing SRAM accesses. This can lead to the use of stale base addresses from previous jobs, potentially causing undefined behavior or data corruption. Organizations using Linux systems that leverage the ethosu accelerator should prioritize addressing this vulnerability to prevent potential exploitation and ensure system stability.

CVE
CVE-2026-97911
Severity
HIGH
CVSS
7.8
EPSS
0.15%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: accel: ethosu: Ensure SRAM region size matches job It is possible for userspace to set the job SRAM size to 0, but then still have SRAM accesses in the command stream. When the job SRAM size is 0, setting the region base register is skipped and a stale base address from a prior job is used. Check the region size against the job's SRAM size instead of just the size of the SRAM. The job's SRAM size was already checked against the total SRAM size.