← All Advisories

CVE-2026-97916

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97916

Key Details

CVECVE-2026-97916
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

accel/ivpu: Validate firmware log buffer metadata

The tracing log headers parsed by fw_log_print_buffer() reside in

DMA-shared BOs that the NPU firmware can write to.

fw_log_from_bo() validated log->header_size and log->size, but

fw_log_print_buffer() re-read those same fields from shared memory

afterwards, allowing a TOCTOU where firmware changes them between the

check and the use, and making the host dereference out-of-bounds

addresses while printing logs.

Snapshot the validated values once with READ_ONCE() and pass them down

explicitly in a new struct ivpu_fw_log_desc instead of re-reading them

from the shared struct. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97916
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97916