OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-98143

HIGH · CVSS 7.8 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of the U65 rounding mode in the ethosu driver, where incorrect interpretation of command stream parameters can lead to command failures and erroneous feature map sizes. This issue primarily impacts devices utilizing the i.MX93 platform, resulting in multiple failures in the Teflon test suite due to misconfigured command streams. Organizations using affected Linux kernel versions on i.MX93 hardware should prioritize addressing this vulnerability to ensure proper functionality and performance of their systems.

CVE
CVE-2026-98143
Severity
HIGH
CVSS
7.8
EPSS
0.11%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: accel: ethosu: Don't read the U65 rounding mode as a storage mode Bits 15:14 of NPU_SET_{IFM,OFM}_PRECISION select the activation storage mode on U85 only. On U65 the same field holds the rounding mode, and the command stream parser has read it as a storage mode since the driver was added. That went unnoticed while unknown values fell through the switch, but now that they are rejected, every U65 command stream that asks for natural rounding (2) fails CMDSTREAM_BO_CREATE with -EINVAL. Mesa emits it for average pooling, concatenation, split, unpack, strided slice, LUT and argmax, which is 72 failures of the Teflon test suite on an i.MX93. Truncating rounding (1) is misread as well: it picks the two-tile address path and computes a bogus feature map size from tile bases the command stream never set. Read the field as a storage mode only on the hardware where it is one.