← All Advisories

CVE-2026-98143

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2026-98143

Key Details

CVECVE-2026-98143
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-09-30
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Kernel

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

accel: ethosu: Don't read the U65 rounding mode as a storage mode

Bits 15:14 of NPU_SET_{IFM,OFM}_PRECISION select the activation storage

mode on U85 only. On U65 the same field holds the rounding mode, and the

command stream parser has read it as a storage mode since the driver was

added.

That went unnoticed while unknown values fell through the switch, but

now that they are rejected, every U65 command stream that asks for

natural rounding (2) fails CMDSTREAM_BO_CREATE with -EINVAL. Mesa emits

it for average pooling, concatenation, split, unpack, strided slice, LUT

and argmax, which is 72 failures of the Teflon test suite on an i.MX93.

Truncating rounding (1) is misread as well: it picks the two-tile

address path and computes a bogus feature map size from tile bases the

command stream never set.

Read the field as a storage mode only on the hardware where it is one. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98143
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98143