Description
In the Linux kernel, the following vulnerability has been resolved:

accel/ethosu: check MMIO mapping errors in probe

devm_platform_ioremap_resource() returns an error pointer when the register
resource cannot be mapped. ethosu_probe() stores it and continues until
initialization dereferences it through MMIO accessors.

Return the mapping error before initializing the device.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (kernel crash)
Action: Immediate Patch
AI Analysis

Impact

The defect resides in the ethosu device driver within the Linux kernel. When the kernel fails to map the required hardware registers, the probe routine stores an error pointer from devm_platform_ioremap_resource() and later dereferences it through memory‑mapped I/O accessors. This unchecked error pointer leads to a kernel crash, rendering the system unstable. The underlying weakness corresponds to the improper handling of error pointers, a typical instance of a NULL or invalid pointer dereference.

Affected Systems

All currently supported Linux kernel releases that include the ethosu driver are affected, as the vulnerability originates from the kernel source itself. The specific versions are not enumerated in the data, so any kernel with the unpatched ethosu probe logic is vulnerable.

Risk and Exploitability

The EPSS score indicates a very low probability of exploitation (<1%). The vulnerability is not listed in CISA's KEV catalog, further suggesting limited active exploitation. Based on the description, it is inferred that the attack vector requires local privileged access to load or trigger the ethosu driver, meaning the primary risk is to systems administered by users with sufficient kernel privileges. The impact is a denial of service via kernel panic, but no known code‑execution path exists in the current data.

Generated by OpenCVE AI on September 17, 2026 at 23:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel patch that introduces a check for MMIO mapping errors in the ethosu probe routine, as referenced in the provided kernel commit URLs.
  • Reboot the system after upgrading the kernel to ensure the patched driver module is used and no stale device instances remain active.
  • If an immediate kernel upgrade is not possible, disable the ethosu driver or the hardware device that loads it until the patch can be applied, preventing the vulnerable probe phase from executing.

Generated by OpenCVE AI on September 17, 2026 at 23:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: check MMIO mapping errors in probe devm_platform_ioremap_resource() returns an error pointer when the register resource cannot be mapped. ethosu_probe() stores it and continues until initialization dereferences it through MMIO accessors. Return the mapping error before initializing the device.
Title accel/ethosu: check MMIO mapping errors in probe
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:55.212Z

Reserved: 2026-09-11T19:38:34.779Z

Link: CVE-2026-89977

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:08.560

Modified: 2026-09-16T11:17:08.560

Link: CVE-2026-89977

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:30:17Z

Weaknesses