{"id":"CVE-2026-89825","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-89825","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panthor: fix firmware control interface bounds checks\n\npanthor_init_cs_iface() and panthor_init_csg_iface()…","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panthor: fix firmware control interface bounds checks\n\npanthor_init_cs_iface() and panthor_init_csg_iface() validate firmware\ncontrol interface offsets with 32-bit arithmetic and the size of the host\nwrapper structures. The offsets are derived from firmware-provided strides,\nso the arithmetic can wrap before the bounds check, and the host wrapper\nsize is not the size of the firmware control interface being mapped.\n\nUse 64-bit arithmetic for the computed offsets and validate against the\nactual firmware control interface structure sizes with subtraction-based\nbounds checks. Also validate that the shared section is large enough for\nthe global control interface before using it.","published":"2026-09-16T10:30:57.497Z","modified":"2026-09-16T10:30:57.497Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/33ae55809aee9b4dca1d00cdee35b527f2bf8626"},{"type":"WEB","url":"https://git.kernel.org/stable/c/80c9528661c774f899281c9a72011208ff39929e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/3e5c7cddc0073eef6f9bb373189b11a969f1f6f6"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6a47f9fd2d970674ed9dedc52fc7ab76fd015785"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-16T10:30:57.497Z"}}