Out-of-bounds write in Linux kernel - CVE-2026-53172

 

Out-of-bounds write in Linux kernel - CVE-2026-53172

Published: June 26, 2026


Vulnerability identifier: #VU135616
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-53172
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to corrupt kernel heap memory.

The vulnerability exists due to an out-of-bounds write in the ethosu command stream parser when processing a crafted NPU_SET_IFM_REGION command from userspace. A local user can supply a region index greater than 7 to corrupt kernel heap memory.

The issue is caused by using the region index directly as an array subscript into the allocated info structure.


Affected software

Linux kernel
Ubuntu
linux (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)

How to mitigate CVE-2026-53172

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13

External References

Related Security Bulletins