7.8

CVE-2026-97577

media: verisilicon: rockchip: reject AV1 frames exceeding the tile capacity

In the Linux kernel, the following vulnerability has been resolved:

media: verisilicon: rockchip: reject AV1 frames exceeding the tile capacity

rockchip_vpu981_av1_dec_set_tile_info() indexes the tile group entry
array by tile1 * tile_cols + tile0, reading up to tile_cols * tile_rows
entries, lays out one descriptor per tile in the AV1_MAX_TILES tile_info
buffer, and programs the real tile_cols / tile_rows into the hardware.

The tile group entry control is a dynamic array sized to the number of
entries userspace submitted, independent of tile_cols / tile_rows, so a
frame that claims more tiles than entries reads past the array. A frame
that claims more than AV1_MAX_TILES tiles also leaves the hardware
programmed for more tiles than the descriptor buffer holds.

Reject both in prepare_run(): tile_cols * tile_rows must not exceed the
submitted entry count or AV1_MAX_TILES. The entry count is read via
v4l2_ctrl_find() (ctrl->elems). This mirrors the bound the mediatek AV1
decoder already enforces.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 727a400686a2c0d25015c9e44916a59b72882f83
Version < 95ee48eb17c91bd4859b65e0a54e7722f370d0e5
Status affected
Version 727a400686a2c0d25015c9e44916a59b72882f83
Version < 40029f7f35397853f8711d6fce1d90a4c7a01f8c
Status affected
Version 727a400686a2c0d25015c9e44916a59b72882f83
Version < a41babf528f70c9a82ed31cfb5fe19065910f7f0
Status affected
Version 727a400686a2c0d25015c9e44916a59b72882f83
Version < fd965369220cc160bb20a24991790814bfbab401
Status affected
Version 727a400686a2c0d25015c9e44916a59b72882f83
Version < 367db8b23c26a913d76ed70457bbcd781c422b49
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.5
Status affected
Version 0
Version < 6.5
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.049
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/40029f7f35397853f8711d6fce1d90a4c7a01f8c
https://git.kernel.org/stable/c/a41babf528f70c9a82ed31cfb5fe19065910f7f0
https://git.kernel.org/stable/c/fd965369220cc160bb20a24991790814bfbab401
https://git.kernel.org/stable/c/367db8b23c26a913d76ed70457bbcd781c422b49
https://git.kernel.org/stable/c/95ee48eb17c91bd4859b65e0a54e7722f370d0e5