Description
In the Linux kernel, the following vulnerability has been resolved:

drm/panthor: fix firmware control interface bounds checks

panthor_init_cs_iface() and panthor_init_csg_iface() validate firmware
control interface offsets with 32-bit arithmetic and the size of the host
wrapper structures. The offsets are derived from firmware-provided strides,
so the arithmetic can wrap before the bounds check, and the host wrapper
size is not the size of the firmware control interface being mapped.

Use 64-bit arithmetic for the computed offsets and validate against the
actual firmware control interface structure sizes with subtraction-based
bounds checks. Also validate that the shared section is large enough for
the global control interface before using it.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption potential
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in the Linux kernel's DRM Panthor driver, where the firmware control interface offsets are calculated using 32‑bit arithmetic. Because the offsets are derived from firmware‑provided strides, the arithmetic can overflow before the bounds checks are performed, and the host wrapper size used does not match the size of the firmware control interface being mapped. This flaw can allow an attacker to supply crafted firmware that causes the device to access memory outside the intended bounds, potentially leading to data corruption or escalation of privileges.

Affected Systems

Affected systems are all Linux kernels that include the Panthor DRM driver, listed by the CNA as Linux:Linux. No specific version range is provided, so any kernel that compiles the Panthor driver without the applied patch is vulnerable. Firmware images or modules that use the Panthor control interface are required for exploitation.

Risk and Exploitability

The CVSS score of 7.8 classifies this flaw as high severity, but the EPSS score of < 1 % indicates that it is currently very unlikely to be actively exploited. The issue is not listed in the CISA KEV catalog. The most likely attack vector is a local attacker who can supply or influence firmware to the Panthor driver; remote exploitation would require additional foothold or privileged access to load malicious code.

Generated by OpenCVE AI on September 18, 2026 at 09:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that contains the panthor bounds‑check patch, ensuring that panthor_init_cs_iface and panthor_init_csg_iface use 64‑bit arithmetic and subtraction‑based bounds checks.
  • Reboot the system after the kernel update so the new kernel is active and the patched code is running.
  • If an update cannot be applied immediately, disable the panthor DRM driver by adding a kernel module blacklist or removing the driver from the system to prevent the vulnerable code path from executing.

Generated by OpenCVE AI on September 18, 2026 at 09:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
CWE-20

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/panthor: fix firmware control interface bounds checks panthor_init_cs_iface() and panthor_init_csg_iface() validate firmware control interface offsets with 32-bit arithmetic and the size of the host wrapper structures. The offsets are derived from firmware-provided strides, so the arithmetic can wrap before the bounds check, and the host wrapper size is not the size of the firmware control interface being mapped. Use 64-bit arithmetic for the computed offsets and validate against the actual firmware control interface structure sizes with subtraction-based bounds checks. Also validate that the shared section is large enough for the global control interface before using it.
Title drm/panthor: fix firmware control interface bounds checks
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:03.420Z

Reserved: 2026-09-11T19:38:34.768Z

Link: CVE-2026-89825

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:49.127

Modified: 2026-09-16T15:18:11.433

Link: CVE-2026-89825

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:15:06Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound

  • CWE-20

    Improper Input Validation