Bug 2541366 (CVE-2026-98143) - CVE-2026-98143 kernel: accel: ethosu: Don't read the U65 rounding mode as a storage mode
Summary: CVE-2026-98143 kernel: accel: ethosu: Don't read the U65 rounding mode as a s...
Keywords:
Status: NEW
Alias: CVE-2026-98143
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-25 11:35 UTC by OSIDB Bzimport
Modified: 2026-09-28 15:49 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-25 11:35:11 UTC
In the Linux kernel, the following vulnerability has been resolved:

accel: ethosu: Don't read the U65 rounding mode as a storage mode

Bits 15:14 of NPU_SET_{IFM,OFM}_PRECISION select the activation storage
mode on U85 only. On U65 the same field holds the rounding mode, and the
command stream parser has read it as a storage mode since the driver was
added.

That went unnoticed while unknown values fell through the switch, but
now that they are rejected, every U65 command stream that asks for
natural rounding (2) fails CMDSTREAM_BO_CREATE with -EINVAL. Mesa emits
it for average pooling, concatenation, split, unpack, strided slice, LUT
and argmax, which is 72 failures of the Teflon test suite on an i.MX93.
Truncating rounding (1) is misread as well: it picks the two-tile
address path and computes a bogus feature map size from tile bases the
command stream never set.

Read the field as a storage mode only on the hardware where it is one.


Note You need to log in before you can comment on or make changes to this bug.