SB20260928289 - Improper initialization in Linux kernel accel ethosu driver
Published: September 28, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper initialization (CVE-ID: CVE-2026-97912)
CWE-ID: CWE-665 - Improper Initialization
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to access SRAM mapped to physical base address 0x0.
The vulnerability exists due to improper state initialization in the Ethos-U SRAM initialization routine when SRAM mapping fails. A local user can submit jobs after an SRAM mapping failure to access SRAM mapped to physical base address 0x0.
The device probe can succeed even when SRAM mapping fails.
Remediation
Install update from vendor's website.