CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's handling of HEVC tile loops and picture parameter set (PPS) IDs, which could lead to out-of-bounds writes in the hardware tables due to untrusted input. This flaw may allow an attacker to exploit the system by manipulating the tile configuration, potentially leading to system instability or unauthorized access. Organizations using Linux kernels that handle HEVC video processing should prioritize patching this vulnerability to mitigate potential risks.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: media: rkvdec: bound HEVC tile loops and PPS id to the array capacity compute_tiles_uniform() and compute_tiles_non_uniform() loop over num_tile_columns_minus1 + 1 / num_tile_rows_minus1 + 1 entries, and assemble_hw_pps() writes one COLUMN_WIDTH / ROW_HEIGHT register per tile and indexes priv_tbl->param_set[] by pic_parameter_set_id, all taken from the untrusted PPS. Use the bounded v4l2_hevc_pps_num_tile_columns() / v4l2_hevc_pps_num_tile_rows() helpers for the tile loops, and bail out of assemble_hw_pps() before indexing priv_tbl->param_set[] with an out-of-range pic_parameter_set_id, so the writes stay within the hardware tables.