OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-97575

HIGH · CVSS 7.8 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of AV1 video decoding, specifically in the validation of tile counts for stateless AV1 decoders. An attacker could exploit this flaw to manipulate tile dimensions, potentially leading to buffer overflows or other unexpected behaviors in media processing. Linux system administrators and developers working with AV1 video decoding should prioritize addressing this issue to mitigate potential security risks.

CVE
CVE-2026-97575
Severity
HIGH
CVSS
7.8
EPSS
0.16%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: media: v4l2-ctrls: validate AV1 tile counts The stateless AV1 decoders use tile_info.tile_cols and tile_rows as loop bounds and as indices into the mi_*_starts[] and *_in_sbs_minus_1[] arrays, as the divisor for context_update_tile_id, and their product bounds the per-tile descriptor buffers, but std_validate_compound() does not bound these u8 fields. Reject a V4L2_CTRL_TYPE_AV1_FRAME whose tile_cols or tile_rows exceeds V4L2_AV1_MAX_TILE_COLS / _ROWS, or whose product exceeds V4L2_AV1_MAX_TILE_COUNT. A zero tile count is left to the consuming driver so the zero-initialised control that existing userspace submits is still accepted.