7.8

CVE-2026-97578

media: verisilicon: rockchip: guard VPU981 AV1 divisor and tile buffer

In the Linux kernel, the following vulnerability has been resolved:

media: verisilicon: rockchip: guard VPU981 AV1 divisor and tile buffer

rockchip_vpu981_av1_dec_set_tile_info() divides context_update_tile_id by
tile_info->tile_cols and writes one descriptor per tile into the tile_info
DMA buffer, which holds AV1_MAX_TILES entries; tile_cols and tile_rows
come from the bitstream. Guard the division against a zero tile_cols by
initialising the context-update values to zero and computing them only
when tile_cols is non-zero, and stop the descriptor writes once the
tile_info buffer is full. The tile geometry written to the hardware
registers is left unmodified; the per-dimension and total tile bounds are
enforced by the control validation.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 727a400686a2c0d25015c9e44916a59b72882f83
Version < 8659e5fc21a82e00fb2db1557f2e06f0fca06b90
Status affected
Version 727a400686a2c0d25015c9e44916a59b72882f83
Version < 7baa7bb1b784c19170df8c99466fa412040eb431
Status affected
Version 727a400686a2c0d25015c9e44916a59b72882f83
Version < 8f19d869a9f6800547c9ad7ebaf3b94f973dab50
Status affected
Version 727a400686a2c0d25015c9e44916a59b72882f83
Version < 6b7a281a815ae7c5e7bb2aad039ffea9bc933157
Status affected
Version 727a400686a2c0d25015c9e44916a59b72882f83
Version < b84f6533a8ed2fd7b282fc7ab4b8efadc745a89c
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.5
Status affected
Version 0
Version < 6.5
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.049
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/7baa7bb1b784c19170df8c99466fa412040eb431
https://git.kernel.org/stable/c/8f19d869a9f6800547c9ad7ebaf3b94f973dab50
https://git.kernel.org/stable/c/6b7a281a815ae7c5e7bb2aad039ffea9bc933157
https://git.kernel.org/stable/c/b84f6533a8ed2fd7b282fc7ab4b8efadc745a89c
https://git.kernel.org/stable/c/8659e5fc21a82e00fb2db1557f2e06f0fca06b90