PT-2026-98515 · Linux · Linux Kernel
CVE-2026-97575
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
Stateless AV1 decoders fail to properly bound the
tile cols and tile rows fields within std validate compound(). These fields are used as loop bounds, as indices for the mi * starts[] and * in sbs minus 1[] arrays, and as a divisor for the context update tile id function. Additionally, the product of these values bounds the per-tile descriptor buffers. This lack of validation can lead to issues when processing a V4L2 CTRL TYPE AV1 FRAME where tile cols or tile rows exceed V4L2 AV1 MAX TILE COLS / V4L2 AV1 MAX TILE ROWS, or when their product exceeds V4L2 AV1 MAX TILE COUNT.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel