OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-97576

HIGH · CVSS 7.8 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of HEVC (High Efficiency Video Coding) tile counts within the media subsystem, specifically in the v4l2-ctrls component. An attacker could exploit this flaw to cause out-of-bounds access by providing invalid tile counts, potentially leading to memory corruption or crashes. Organizations using Linux systems with HEVC decoding capabilities should prioritize addressing this issue to mitigate risks associated with media processing vulnerabilities.

CVE
CVE-2026-97576
Severity
HIGH
CVSS
7.8
EPSS
0.16%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: media: v4l2-ctrls: validate HEVC tile counts The stateless HEVC decoders read num_tile_columns_minus1 + 1 entries from column_width_minus1[] and num_tile_rows_minus1 + 1 from row_height_minus1[] and use them as tile-loop bounds, but std_validate_compound() does not bound these u8 counts. Reject a V4L2_CTRL_TYPE_HEVC_PPS with tiling enabled whose tile counts exceed the uAPI array capacity, mirroring the existing compound-control range checks.