{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89825","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.768Z","datePublished":"2026-09-16T10:30:57.497Z","dateUpdated":"2026-09-16T14:39:03.420Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-16T14:39:03.420Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panthor: fix firmware control interface bounds checks\n\npanthor_init_cs_iface() and panthor_init_csg_iface() validate firmware\ncontrol interface offsets with 32-bit arithmetic and the size of the host\nwrapper structures. The offsets are derived from firmware-provided strides,\nso the arithmetic can wrap before the bounds check, and the host wrapper\nsize is not the size of the firmware control interface being mapped.\n\nUse 64-bit arithmetic for the computed offsets and validate against the\nactual firmware control interface structure sizes with subtraction-based\nbounds checks. Also validate that the shared section is large enough for\nthe global control interface before using it."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The 32-bit stride overflow is reached only on the local panthor probe path (panthor_probe → panthor_device_init → panthor_fw_init → panthor_fw_start → panthor_fw_init_ifaces → panthor_init_csg_iface/panthor_init_cs_iface) when mapping firmware-provided group_stride/stream_stride from mali_csffw.bin; no network, Bluetooth, or USB handler feeds those fields.\nAC:L - Firmware fully controls group_stride, stream_stride, and group_num (MIN_CSGS is 3, so csg_idx>=1 always runs). A crafted stride that places the u32 offset near 2^32 makes offset+sizeof wrap to a small value and pass the bounds check deterministically, with no race or attacker-uncontrollable timing.\nPR:L - The parser applies no capability check to firmware contents. On Mali CSF Android phones, Chromebooks, and embedded boards, mali_csffw.bin commonly lives on vendor/firmware partitions writable by local non-root system or vendor service accounts, which is sufficient to plant the crafted blob before driver probe.\nUI:N - Once the crafted firmware is in place, panthor_fw_init_ifaces() runs automatically at driver probe and caches the resulting interface pointers; no separate victim action such as opening a file, mounting a filesystem, or using /dev/dri is required to trigger the overflow.\nS:U - The bug corrupts kernel memory past the firmware shared-section vmap and can enable local privilege escalation within the host kernel; it does not cross a VM, IOMMU, or sandbox boundary such as a KVM guest-to-host escape.\nC:H - A wrapped u32 iface_offset near 2^32 yields kmap plus a ~4GiB out-of-bounds control pointer; the kernel then reads panthor_fw_*_control_iface fields (input_va, output_va, stream_num, stream_stride, features) from that address, disclosing kernel memory rather than a few bounded bytes.\nI:H - Those OOB control pointers are cached for the device lifetime and consumed by scheduler, job-IRQ, and GROUP_CREATE paths that write panthor_fw_*_input_iface structures and allocate suspend buffers from control->suspend_size, enabling out-of-bounds kernel writes and control-flow hijacking.\nA:H - Dereferencing kmap plus a wrapped near-4GiB offset can immediately oops or panic if the region is unmapped, and a corrupted firmware interface leaves the Mali GPU unusable; the same path is hit on every probe or firmware boot until the blob is removed."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/panthor/panthor_fw.c"],"versions":[{"version":"2718d91816eeed03c09c8abe872e45f59078768c","lessThan":"33ae55809aee9b4dca1d00cdee35b527f2bf8626","status":"affected","versionType":"git"},{"version":"2718d91816eeed03c09c8abe872e45f59078768c","lessThan":"80c9528661c774f899281c9a72011208ff39929e","status":"affected","versionType":"git"},{"version":"2718d91816eeed03c09c8abe872e45f59078768c","lessThan":"3e5c7cddc0073eef6f9bb373189b11a969f1f6f6","status":"affected","versionType":"git"},{"version":"2718d91816eeed03c09c8abe872e45f59078768c","lessThan":"6a47f9fd2d970674ed9dedc52fc7ab76fd015785","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/panthor/panthor_fw.c"],"versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/33ae55809aee9b4dca1d00cdee35b527f2bf8626"},{"url":"https://git.kernel.org/stable/c/80c9528661c774f899281c9a72011208ff39929e"},{"url":"https://git.kernel.org/stable/c/3e5c7cddc0073eef6f9bb373189b11a969f1f6f6"},{"url":"https://git.kernel.org/stable/c/6a47f9fd2d970674ed9dedc52fc7ab76fd015785"}],"title":"drm/panthor: fix firmware control interface bounds checks","x_generator":{"engine":"bippy-1.2.0"}}}}