---
id: CVE-2026-89825
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  drm/panthor: fix firmware control interface bounds checks

  panthor_init_cs_iface() and panthor_init_csg_iface() validate firmware
  control interface offsets with 32-bit …
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  drm/panthor: fix firmware control interface bounds checks

  panthor_init_cs_iface() and panthor_init_csg_iface() validate firmware
  control interface offsets with 32-bit …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 2718d91816eeed03c09c8abe872e45f59078768c <
    33ae55809aee9b4dca1d00cdee35b527f2bf8626
  - >-
    Linux >= 2718d91816eeed03c09c8abe872e45f59078768c <
    80c9528661c774f899281c9a72011208ff39929e
  - >-
    Linux >= 2718d91816eeed03c09c8abe872e45f59078768c <
    3e5c7cddc0073eef6f9bb373189b11a969f1f6f6
  - >-
    Linux >= 2718d91816eeed03c09c8abe872e45f59078768c <
    6a47f9fd2d970674ed9dedc52fc7ab76fd015785
  - Linux 6.10
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T15:18:11.433'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89825'
references:
  - url: 'https://git.kernel.org/stable/c/33ae55809aee9b4dca1d00cdee35b527f2bf8626'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/3e5c7cddc0073eef6f9bb373189b11a969f1f6f6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6a47f9fd2d970674ed9dedc52fc7ab76fd015785'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/80c9528661c774f899281c9a72011208ff39929e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-16T10:53:54.001Z'
epss: 0.00175
epssPercentile: 0.06158
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

drm/panthor: fix firmware control interface bounds checks

panthor_init_cs_iface() and panthor_init_csg_iface() validate firmware
control interface offsets with 32-bit arithmetic and the size of the host
wrapper structures. The offsets are derived from firmware-provided strides,
so the arithmetic can wrap before the bounds check, and the host wrapper
size is not the size of the firmware control interface being mapped.

Use 64-bit arithmetic for the computed offsets and validate against the
actual firmware control interface structure sizes with subtraction-based
bounds checks. Also validate that the shared section is large enough for
the global control interface before using it.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
