Description
In the Linux kernel, the following vulnerability has been resolved:

drm/panthor: harden firmware build-info bounds checks

panthor_fw_read_build_info() checks whether the metadata range fits in the
firmware image with hdr.meta_start + hdr.meta_size. Both fields are u32, so
the addition can wrap and let an out-of-bounds range pass validation.

The function also reads the "git_sha: " prefix without first checking that
the metadata is long enough, and meta_size == 0 can underflow the NULL
terminator index.

Use subtraction-based bounds checking and reject metadata that is too short
to contain the expected prefix and trailing NULL byte.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch Now
AI Analysis

Impact

A bounds-checking flaw in the Linux kernel’s panthor firmware loader allows an overflow when adding the metadata start and size values, which can cause an out‑of‑bounds range to pass validation. The loader also reads a ‘git_sha: ’ prefix without verifying that the metadata is long enough, and a zero size can underflow the NULL terminator index. An attacker who can supply crafted firmware metadata may exploit this to read or corrupt kernel memory, potentially leading to privilege escalation or arbitrary code execution. The vulnerability is classified as an integer overflow or wraparound and a buffer overread.

Affected Systems

This flaw exists in the Linux kernel wherever the drm/panthor firmware loading path is present. No specific kernel release versions are listed in the advisory; any kernel that contains the panthor_fw_read_build_info function is potentially affected.

Risk and Exploitability

The CVSS 7.1 score indicates high impact if exploited. EPSS is under 1%, suggesting the probability of exploitation is low at present. The vulnerability is not listed in the CISA KEV catalog, and the attack likely requires an attacker to supply malicious firmware to the DRM subsystem, implying local or privileged access. Without readily available exploit code and given the low EPSS, the overall risk remains moderate but non‑negligible.

Generated by OpenCVE AI on September 18, 2026 at 09:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that contains the panthor firmware bounds‑check patch.
  • If the patch cannot be applied immediately, disable the panthor firmware loading path or restrict firmware loading to trusted sources only.
  • Ensure that any firmware image loaded into the system includes the required ‘git_sha: ’ prefix and a trailing NUL byte to satisfy the sanity checks implemented by the patch.

Generated by OpenCVE AI on September 18, 2026 at 09:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-190

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/panthor: harden firmware build-info bounds checks panthor_fw_read_build_info() checks whether the metadata range fits in the firmware image with hdr.meta_start + hdr.meta_size. Both fields are u32, so the addition can wrap and let an out-of-bounds range pass validation. The function also reads the "git_sha: " prefix without first checking that the metadata is long enough, and meta_size == 0 can underflow the NULL terminator index. Use subtraction-based bounds checking and reject metadata that is too short to contain the expected prefix and trailing NULL byte.
Title drm/panthor: harden firmware build-info bounds checks
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:04.631Z

Reserved: 2026-09-11T19:38:34.769Z

Link: CVE-2026-89826

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:49.253

Modified: 2026-09-16T15:18:11.553

Link: CVE-2026-89826

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:15:06Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-190

    Integer Overflow or Wraparound