{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.0.13-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  accel/ethosu: fix IFM region index out-of-bounds in command stream parser  NPU_SET_IFM_REGION extracts the region index with param \u0026 0x7f, giving a maximum value of 127. However region_size[] and output_region[] in struct ethosu_validated_cmdstream_info are both sized to NPU_BASEP_REGION_MAX (8), giving valid indices [0..7].  Every other region assignment in the same switch uses param \u0026 0x7:   NPU_SET_OFM_REGION:  st.ofm.region  = param \u0026 0x7;   NPU_SET_IFM2_REGION: st.ifm2.region = param \u0026 0x7;   NPU_SET_WEIGHT_REGION: st.weight[0].region = param \u0026 0x7;   NPU_SET_SCALE_REGION:  st.scale[0].region  = param \u0026 0x7;  The 0x7f mask on IFM is inconsistent and appears to be a typo.  feat_matrix_length() and calc_sizes() use the region index directly as an array subscript into the kzalloc'd info struct:   info-\u003eregion_size[fm-\u003eregion] = max(...);  A userspace caller supplying NPU_SET_IFM_REGION with param \u003e 7 causes a write up to 127*8 = 1016 bytes past the start of region_size[], corrupting adjacent kernel heap data.  Fix by applying the same \u0026 0x7 mask used by all other region assignments.",
  "id": "DEBIAN-CVE-2026-53172",
  "modified": "2026-09-14T16:47:34.087059024Z",
  "published": "2026-06-25T09:16:34.550Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-53172"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-53172"
  ]
}