OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-97579

HIGH · CVSS 7.8 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's MediaTek video codec, specifically in the `vdec_av1_slice_setup_tile()` function, which improperly copies data beyond the allocated array size for tile start information. This flaw could lead to potential buffer overflows, resulting in memory corruption or system crashes. Linux system administrators and developers utilizing MediaTek hardware should prioritize applying patches to mitigate the risk of exploitation.

CVE
CVE-2026-97579
Severity
HIGH
CVSS
7.8
EPSS
0.16%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: bound AV1 tile-start copy to the array capacity vdec_av1_slice_setup_tile() copies tile_cols + 1 / tile_rows + 1 entries into mi_col_starts[] / mi_row_starts[] from the bitstream tile_info. Bound the copy to the array capacity.