Improper initialization in Linux kernel - CVE-2026-97912

 

Improper initialization in Linux kernel - CVE-2026-97912

Published: September 28, 2026


Vulnerability identifier: #VU152555
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-97912
CWE-ID: CWE-665
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to access SRAM mapped to physical base address 0x0.

The vulnerability exists due to improper state initialization in the Ethos-U SRAM initialization routine when SRAM mapping fails. A local user can submit jobs after an SRAM mapping failure to access SRAM mapped to physical base address 0x0.

The device probe can succeed even when SRAM mapping fails.


Affected software

Linux kernel

How to mitigate CVE-2026-97912

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins