CVE-2026-53205

high

Description

In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Add bounds checks for firmware log indices Add validation that read and write indices in the firmware log buffer are within valid bounds (< data_size) before using them. If out-of-bounds indices are encountered (from firmware), clamp them to safe values instead of proceeding with invalid offsets. This prevents potential out-of-bounds buffer access when firmware supplies invalid log indices.

References

https://git.kernel.org/stable/c/dd1311bcf0e62f0c515115f46a3813370f4a4bb1

https://git.kernel.org/stable/c/8ec70c0dbdf04392a26e03e38798a373934177be

https://git.kernel.org/stable/c/5961c703414048f46818be8bbb11075a9a63fb4e

https://git.kernel.org/stable/c/535da9ad8420c3b686a642403d4147ff220255fd

Details

Source: Mitre, NVD

Published: 2026-06-25

Updated: 2026-06-28

Risk Information

CVSS v2

Base Score: 6.2

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Severity: High

EPSS

EPSS: 0.00175