PatchSiren cyber security CVE debrief
CVE-2026-97912 Linux CVE debrief
A Linux kernel vulnerability was resolved in the accel: ethosu component, ensuring SRAM size is 0 on mapping failure. This issue allowed jobs to access SRAM pointing to physical base address 0x0 after a mapping failure. The vulnerability requires verification of kernel versions and assessment of exposure in systems using this component. The accel: ethosu component is used in Linux kernel deployments, and its vulnerability could lead to potential security risks if not addressed. The issue was resolved through a patch that ensures proper handling of SRAM mapping failures.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-25
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-25
- Advisory updated
- 2026-09-25
Who should care
Linux kernel maintainers, developers, and users of systems with the accel: ethosu component should assess exposure and verify kernel versions. The vulnerability in the accel: ethosu component may affect various Linux kernel deployments, and its resolution requires the attention of Linux kernel maintainers, developers, and users. The assessment of exposure and verification of kernel versions are crucial to ensure the security of systems using this component
Why it matters
The Linux kernel vulnerability in the accel: ethosu component requires verification of kernel versions and assessment of exposure in systems using this component.
- Verify Linux kernel versions for potential exposure
- Assess systems using the accel: ethosu component for vulnerability
- Monitor for potential security updates or patches
Technical summary
The Linux kernel vulnerability was resolved in the accel: ethosu component. The issue occurred when a mapping failure of the SRAM left the SRAM size as non-zero, allowing jobs to access SRAM pointing to physical base address 0x0. The vulnerability requires verification of kernel versions and assessment of exposure in systems using this component. The issue was resolved through a patch that ensures proper handling of SRAM mapping failures. The patch prevents jobs from accessing SRAM with a non-zero size after a mapping failure, thereby mitigating the vulnerability.
Defensive priority
Verify Linux kernel versions and assess exposure in systems using the accel: ethosu component.
Recommended defensive actions
- Verify Linux kernel versions for potential exposure
- Assess systems using the accel: ethosu component for vulnerability
- Monitor for potential security updates or patches
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. Further verification is required to determine affected versions and potential impact. The accel: ethosu component is a part of the Linux kernel, and its vulnerability may affect various Linux kernel deployments. The lack of detailed information in the CVE record and NVD entry necessitates additional research to understand the vulnerability's scope and potential consequences. The Linux kernel maintainers and developers should verify kernel versions and '
Sources and references
Verified primary and authoritative sources
-
CVE-2026-97912 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-97912
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-97912 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97912
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/e5576641b79ecd36acaf91fec4a5333b1ad19c57
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/f5376d7e0fb703876199d3b6f9f97e128fa2f8a4
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.