OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-97580

HIGH · CVSS 7.8 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of HEVC tile loops and picture parameter set (PPS) IDs, which could lead to out-of-bounds writes in the hardware tables due to untrusted input. This flaw may allow an attacker to exploit the system by manipulating the tile configuration, potentially leading to system instability or unauthorized access. Organizations using Linux kernels that handle HEVC video processing should prioritize patching this vulnerability to mitigate potential risks.

CVE
CVE-2026-97580
Severity
HIGH
CVSS
7.8
EPSS
0.15%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: media: rkvdec: bound HEVC tile loops and PPS id to the array capacity compute_tiles_uniform() and compute_tiles_non_uniform() loop over num_tile_columns_minus1 + 1 / num_tile_rows_minus1 + 1 entries, and assemble_hw_pps() writes one COLUMN_WIDTH / ROW_HEIGHT register per tile and indexes priv_tbl->param_set[] by pic_parameter_set_id, all taken from the untrusted PPS. Use the bounded v4l2_hevc_pps_num_tile_columns() / v4l2_hevc_pps_num_tile_rows() helpers for the tile loops, and bail out of assemble_hw_pps() before indexing priv_tbl->param_set[] with an out-of-range pic_parameter_set_id, so the writes stay within the hardware tables.