7.1

CVE-2026-72089

accel/ivpu: Reject firmware log with size smaller than header

In the Linux kernel, the following vulnerability has been resolved:

accel/ivpu: Reject firmware log with size smaller than header

fw_log_from_bo() validates the tracing buffer header_size and that the
log fits within the BO, but never checks that log->size is at least
log->header_size. fw_log_print_buffer() then computes:

  u32 data_size = log->size - log->header_size;

which underflows to a near-U32_MAX value when firmware reports a log whose
size is smaller than its header. That huge data_size defeats the
log_start/log_end bounds clamps added by commit dd1311bcf0e6 ("accel/ivpu:
Add bounds checks for firmware log indices"), so fw_log_print_lines() reads
far past the small real data region of the BO. A size of 0 also makes
fw_log_from_bo() advance the offset by 0, causing the callers to loop
forever on the same header.

Reject logs whose size is smaller than the header (which also rejects
size == 0).
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version d4e4257afa6ed5205eda993180401fc2c20e4b60
Version < 5592a207e158b738d9c1d27f208dbbea13ae7606
Status affected
Version d4e4257afa6ed5205eda993180401fc2c20e4b60
Version < dc9a1cda2e46d0254730a6f93cfe48532895f33c
Status affected
Version d4e4257afa6ed5205eda993180401fc2c20e4b60
Version < 257321a1c036da417f5d9c47b95c7e58f62bf263
Status affected
Version d4e4257afa6ed5205eda993180401fc2c20e4b60
Version < 6920e62be4c969a68ce4ebc59da68c6cbc9512e5
Status affected
Version d4e4257afa6ed5205eda993180401fc2c20e4b60
Version < ddb44baed257560f192b145ed36cf8c0a412de47
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.6
Status affected
Version 0
Version < 6.6
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.063
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/5592a207e158b738d9c1d27f208dbbea13ae7606
https://git.kernel.org/stable/c/dc9a1cda2e46d0254730a6f93cfe48532895f33c
https://git.kernel.org/stable/c/257321a1c036da417f5d9c47b95c7e58f62bf263
https://git.kernel.org/stable/c/6920e62be4c969a68ce4ebc59da68c6cbc9512e5
https://git.kernel.org/stable/c/ddb44baed257560f192b145ed36cf8c0a412de47