In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Validate full buffer range in ivpu_to_cpu_addr Add a size parameter to ivpu_to_cpu_addr() and validate that the whole [vpu_addr, vpu_addr + size) range stays within the BO.
https://git.kernel.org/stable/c/5419be345f32222750e006b85b7f9bae1a285c8e
https://git.kernel.org/stable/c/43c68f52aecd519eb682fa09d57ae52c896f860f
https://git.kernel.org/stable/c/3837c3f29fbc3b8c12bebf5c62741e2befe3482a
https://git.kernel.org/stable/c/29f82a2280e170429370e7a842cde4e70ead8547