Linux kernel: ethosu driver misinterprets rounding mode leading to failures
CVE-2026-98143 Published on September 25, 2026
accel: ethosu: Don't read the U65 rounding mode as a storage mode
In the Linux kernel, the following vulnerability has been resolved:
accel: ethosu: Don't read the U65 rounding mode as a storage mode
Bits 15:14 of NPU_SET_{IFM,OFM}_PRECISION select the activation storage
mode on U85 only. On U65 the same field holds the rounding mode, and the
command stream parser has read it as a storage mode since the driver was
added.
That went unnoticed while unknown values fell through the switch, but
now that they are rejected, every U65 command stream that asks for
natural rounding (2) fails CMDSTREAM_BO_CREATE with -EINVAL. Mesa emits
it for average pooling, concatenation, split, unpack, strided slice, LUT
and argmax, which is 72 failures of the Teflon test suite on an i.MX93.
Truncating rounding (1) is misread as well: it picks the two-tile
address path and computes a bogus feature map size from tile bases the
command stream never set.
Read the field as a storage mode only on the hardware where it is one.
Products Associated with CVE-2026-98143
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 5a5e9c0228e613f0ef2a58b9782d7c0ea8f1e58b and below 6b08adbda8ea797849e3654ce12cb3856ce6051a is affected.
- Version 5a5e9c0228e613f0ef2a58b9782d7c0ea8f1e58b and below db9deec5a345abc538d081fb221dc0b00a9695bd is affected.
- Version 6.19 is affected.
- Before 6.19 is unaffected.
- Version 7.2.7, <= 7.2.* is unaffected.
- Version 7.3-rc2, <= * is unaffected.