Junglewise Threat Intelligence

CVE-2026-53170: Linux Kernel Arm Ethos-U NPU bounds check bypass in DMA commands

CVE-2026-53170 · Severity: info · CVSS 0 · Published 2026-06-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Arm Ethos-U NPU driver could allow a local user to bypass security checks. This driver manages specialized hardware used for accelerating artificial intelligence tasks. By sending specific malformed commands, an attacker could cause the hardware to perform memory operations using incorrect addresses, potentially leading to unauthorized data access or system instability.

Technical details

An integer wrapping vulnerability exists in the 'accel/ethosu' driver within the Linux kernel. The 'cmd_state_init()' function initializes DMA length to U64_MAX as a sentinel value. If a userspace attacker omits the 'NPU_SET_DMA0_LEN' command and issues 'NPU_OP_DMA_START', the 'dma_length()' function performs arithmetic on the U64_MAX value. A positive stride can cause the length to wrap to a small value, bypassing the 'check_mul_overflow()' and subsequent U64_MAX checks. This results in a 'region_size' of 0, effectively bypassing bounds checks in 'ethosu_job.c' and allowing the hardware to execute DMA operations using stale physical addresses. The fix introduces an explicit check for the U64_MAX sentinel before arithmetic operations.

Affected products

  • Linux Linux Kernel 6.19, 7.0.13, 7.1

Timeline

  • 2026-06-25: advisory: NVD publication date
  • 2026-06-04: patched: Initial fix committed to stable tree

References

Related threats