SB20260928289 - Improper initialization in Linux kernel accel ethosu driver



SB20260928289 - Improper initialization in Linux kernel accel ethosu driver

Published: September 28, 2026 Updated: September 30, 2026

Security Bulletin ID SB20260928289
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper initialization (CVE-ID: CVE-2026-97912)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access SRAM mapped to physical base address 0x0.

The vulnerability exists due to improper state initialization in the Ethos-U SRAM initialization routine when SRAM mapping fails. A local user can submit jobs after an SRAM mapping failure to access SRAM mapped to physical base address 0x0.

The device probe can succeed even when SRAM mapping fails.


Remediation

Install update from vendor's website.