Description
In the Linux kernel, the following vulnerability has been resolved:

accel/ethosu: fix job completion fence cleanup

ethosu_ioctl_submit_job() allocates done_fence before validating buffer
handles. Errors after allocation call ethosu_job_err_cleanup(), which frees
the job but leaks the uninitialized fence.

A scheduler dependency error also lets ethosu_job_run() return before
dma_fence_init(). Normal cleanup then passes a zeroed refcount to
dma_fence_put().

Release done_fence in the common cleanup path and use
dma_fence_was_initialized() to distinguish initialized fences from raw
allocations.

[robh: also fix goto]
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource Leak / Potential Denial of Service
Action: Patch
AI Analysis

Impact

The Linux kernel driver for the ARM Ethos‑U accelerator allocates a job completion fence without validating job buffers. Errors after the allocation trigger a cleanup path that frees the job but leaks the uninitialized fence. Additionally, a scheduler race allows the job run routine to return before the fence is fully initialized, resulting in a zero‑refcount dwarf that is passed to the fence finalizer. These errors can lead to kernel memory corruption or a subtle resource leak that may cause out‑of‑balance refcount handling, eventually resulting in a kernel panic or a denial‑of‑service condition. The vulnerability directly affects the integrity and availability of the kernel’s synchronization primitives and exposes the system to crashes or memory inconsistencies whenever a user or application submits a job to the Ethos‑U device.

Affected Systems

The flaw exists in the Linux:Linux kernel, specifically within the accel/ethosu component that manages Ethos‑U accelerator jobs. Any system that runs a kernel version containing the unpatched Ethos‑U driver—commonly used on ARM‑based embedded or mobile devices—could be affected. The vendor product list does not specify exact kernel releases, so administrators should check whether their current kernel pulls in the accel/ethosu code and whether it matches the commit that introduced the fix.

Risk and Exploitability

The EPSS score is listed as less than 1 %, indicating a very low probability of exploitation, and the vulnerability is not flagged in the CISA KEV catalog. No CVSS score is provided, but the potential to trigger a kernel panic or memory corruption suggests a moderate severity. The likely attack vector is local: an attacker with access to the Ethos‑U control interface (through the ioctl API) could submit malformed jobs. If the device is exposed via a network‑bound daemon or service, remote exploitation may also be feasible. Given the resource leak and possible crash, the risk is tempered by the low exploitation probability, but the impact of a kernel panic warrants prompt action.

Generated by OpenCVE AI on September 18, 2026 at 07:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to the latest stable release that includes the Ethos‑U driver fix.
  • If an immediate kernel upgrade is not possible, disable the accel/ethosu module or remove the Ethos‑U device from use to avoid the vulnerable code path.
  • Apply the patch manually by incorporating the commit that releases the done_fence in the cleanup path and uses dma_fence_was_initialized() in your local kernel source before rebuilding the module.

Generated by OpenCVE AI on September 18, 2026 at 07:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-391

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: fix job completion fence cleanup ethosu_ioctl_submit_job() allocates done_fence before validating buffer handles. Errors after allocation call ethosu_job_err_cleanup(), which frees the job but leaks the uninitialized fence. A scheduler dependency error also lets ethosu_job_run() return before dma_fence_init(). Normal cleanup then passes a zeroed refcount to dma_fence_put(). Release done_fence in the common cleanup path and use dma_fence_was_initialized() to distinguish initialized fences from raw allocations. [robh: also fix goto]
Title accel/ethosu: fix job completion fence cleanup
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:54.518Z

Reserved: 2026-09-11T19:38:34.779Z

Link: CVE-2026-89976

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:08.450

Modified: 2026-09-16T11:17:08.450

Link: CVE-2026-89976

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:30:05Z

Weaknesses
  • CWE-391

    Unchecked Error Condition