PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-97912 Linux CVE debrief

A Linux kernel vulnerability was resolved in the accel: ethosu component, ensuring SRAM size is 0 on mapping failure. This issue allowed jobs to access SRAM pointing to physical base address 0x0 after a mapping failure. The vulnerability requires verification of kernel versions and assessment of exposure in systems using this component. The accel: ethosu component is used in Linux kernel deployments, and its vulnerability could lead to potential security risks if not addressed. The issue was resolved through a patch that ensures proper handling of SRAM mapping failures.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-25
Advisory published
2026-09-25
Advisory updated
2026-09-25

Who should care

Linux kernel maintainers, developers, and users of systems with the accel: ethosu component should assess exposure and verify kernel versions. The vulnerability in the accel: ethosu component may affect various Linux kernel deployments, and its resolution requires the attention of Linux kernel maintainers, developers, and users. The assessment of exposure and verification of kernel versions are crucial to ensure the security of systems using this component

Why it matters

The Linux kernel vulnerability in the accel: ethosu component requires verification of kernel versions and assessment of exposure in systems using this component.

  • Verify Linux kernel versions for potential exposure
  • Assess systems using the accel: ethosu component for vulnerability
  • Monitor for potential security updates or patches

Technical summary

The Linux kernel vulnerability was resolved in the accel: ethosu component. The issue occurred when a mapping failure of the SRAM left the SRAM size as non-zero, allowing jobs to access SRAM pointing to physical base address 0x0. The vulnerability requires verification of kernel versions and assessment of exposure in systems using this component. The issue was resolved through a patch that ensures proper handling of SRAM mapping failures. The patch prevents jobs from accessing SRAM with a non-zero size after a mapping failure, thereby mitigating the vulnerability.

Defensive priority

Verify Linux kernel versions and assess exposure in systems using the accel: ethosu component.

Recommended defensive actions

  • Verify Linux kernel versions for potential exposure
  • Assess systems using the accel: ethosu component for vulnerability
  • Monitor for potential security updates or patches
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. Further verification is required to determine affected versions and potential impact. The accel: ethosu component is a part of the Linux kernel, and its vulnerability may affect various Linux kernel deployments. The lack of detailed information in the CVE record and NVD entry necessitates additional research to understand the vulnerability's scope and potential consequences. The Linux kernel maintainers and developers should verify kernel versions and '

Sources and references

Verified primary and authoritative sources

  • CVE-2026-97912 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-97912

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-97912 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97912

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e5576641b79ecd36acaf91fec4a5333b1ad19c57

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/f5376d7e0fb703876199d3b6f9f97e128fa2f8a4

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.