{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89826","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.769Z","datePublished":"2026-09-16T10:30:58.435Z","dateUpdated":"2026-09-16T14:39:04.631Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-16T14:39:04.631Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panthor: harden firmware build-info bounds checks\n\npanthor_fw_read_build_info() checks whether the metadata range fits in the\nfirmware image with hdr.meta_start + hdr.meta_size. Both fields are u32, so\nthe addition can wrap and let an out-of-bounds range pass validation.\n\nThe function also reads the \"git_sha: \" prefix without first checking that\nthe metadata is long enough, and meta_size == 0 can underflow the NULL\nterminator index.\n\nUse subtraction-based bounds checking and reject metadata that is too short\nto contain the expected prefix and trailing NULL byte."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The out-of-bounds reads occur only while panthor_fw_load() parses mali_csffw.bin from the local firmware search path at platform probe (panthor_probe→panthor_fw_init→panthor_fw_load_entry→panthor_fw_read_build_info); no network, DRM ioctl, or /dev/dri/renderD* path supplies attacker-controlled build-info headers.\nAC:L - An attacker fully controls the BUILD_INFO_METADATA u32 meta_start and meta_size fields. Setting both to 0, using meta_size shorter than the git_sha prefix, or wrapping meta_start+meta_size deterministically bypasses the old addition check and performs the OOB memcmp, terminator, and %s reads on every load with no race.\nPR:L - panthor_fw_read_build_info() performs no capability or authentication checks on firmware content; on Mali CSF Android, Chromebook, and embedded deployments the GPU firmware image commonly lives on vendor/firmware partitions writable by local non-root system or vendor service accounts, sufficient to plant the crafted blob before driver probe.\nUI:N - After the malicious mali_csffw.bin is in the firmware search path, panthor_fw_read_build_info() runs automatically during driver probe at boot or bind; no separate victim action such as opening a device node or mounting a filesystem is required.\nS:U - The out-of-bounds kernel reads and any resulting oops remain inside the host kernel that loads the Panthor firmware; this is not a VM escape, IOMMU bypass, or other cross-authority breakout.\nC:H - A wrapping or zero meta_size lets drm_info(\"%s\") walk from the git_sha prefix through kernel memory adjacent to the firmware vmalloc buffer until a NUL, and meta_start==0 with meta_size==0 indexes fw->data[0xFFFFFFFF]; these are unbounded out-of-bounds reads, not a few-byte leak.\nI:N - panthor_fw_read_build_info() only memcmp()s, indexes, and prints firmware bytes; the wrapping metadata range is never used as a write destination, so there is no out-of-bounds write, use-after-free, or control-flow hijack primitive.\nA:H - Firmware blobs are vmalloc allocations with guard pages, so the 0xFFFFFFFF terminator index (meta_start=meta_size=0) or an unbounded drm_info %s walk past fw->size readily faults into an unmapped page and oopses or panics the kernel during Mali/Panthor GPU probe."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/panthor/panthor_fw.c"],"versions":[{"version":"2718d91816eeed03c09c8abe872e45f59078768c","lessThan":"5516f1acfd07564361cf306cc90a8e513df0f096","status":"affected","versionType":"git"},{"version":"2718d91816eeed03c09c8abe872e45f59078768c","lessThan":"6ae19dce3e8c13ae73590b3f4311abe9f96bbae8","status":"affected","versionType":"git"},{"version":"2718d91816eeed03c09c8abe872e45f59078768c","lessThan":"8321b093fa6c297b80586460ce6914d9655df170","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/panthor/panthor_fw.c"],"versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/5516f1acfd07564361cf306cc90a8e513df0f096"},{"url":"https://git.kernel.org/stable/c/6ae19dce3e8c13ae73590b3f4311abe9f96bbae8"},{"url":"https://git.kernel.org/stable/c/8321b093fa6c297b80586460ce6914d9655df170"}],"title":"drm/panthor: harden firmware build-info bounds checks","x_generator":{"engine":"bippy-1.2.0"}}}}