7.8

CVE-2026-97575

media: v4l2-ctrls: validate AV1 tile counts

In the Linux kernel, the following vulnerability has been resolved:

media: v4l2-ctrls: validate AV1 tile counts

The stateless AV1 decoders use tile_info.tile_cols and tile_rows as loop
bounds and as indices into the mi_*_starts[] and *_in_sbs_minus_1[]
arrays, as the divisor for context_update_tile_id, and their product
bounds the per-tile descriptor buffers, but std_validate_compound() does
not bound these u8 fields. Reject a V4L2_CTRL_TYPE_AV1_FRAME whose
tile_cols or tile_rows exceeds V4L2_AV1_MAX_TILE_COLS / _ROWS, or whose
product exceeds V4L2_AV1_MAX_TILE_COUNT. A zero tile count is left to the
consuming driver so the zero-initialised control that existing userspace
submits is still accepted.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 9de30f579980b498606a9c2440b73ae3b670771b
Version < 1afaf85c4990fb1e3168d0d6e99246a65e526f1b
Status affected
Version 9de30f579980b498606a9c2440b73ae3b670771b
Version < 85df9fc79b07f1cc7c953f930ae7e675d0c1e820
Status affected
Version 9de30f579980b498606a9c2440b73ae3b670771b
Version < c8891da0186fe4c04bccbbd7d84b01a3c941ac7a
Status affected
Version 9de30f579980b498606a9c2440b73ae3b670771b
Version < c4c88b5ba85685043d171e0e9c9d00a8cf6a89e8
Status affected
Version 9de30f579980b498606a9c2440b73ae3b670771b
Version < 439058ced617fbb3febc017b9e93bb7387f309e0
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.5
Status affected
Version 0
Version < 6.5
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.049
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/85df9fc79b07f1cc7c953f930ae7e675d0c1e820
https://git.kernel.org/stable/c/c8891da0186fe4c04bccbbd7d84b01a3c941ac7a
https://git.kernel.org/stable/c/c4c88b5ba85685043d171e0e9c9d00a8cf6a89e8
https://git.kernel.org/stable/c/439058ced617fbb3febc017b9e93bb7387f309e0
https://git.kernel.org/stable/c/1afaf85c4990fb1e3168d0d6e99246a65e526f1b