PT-2026-98520 · Linux · Linux Kernel

CVE-2026-97580

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the rkvdec media component where the compute tiles uniform() and compute tiles non uniform() functions loop over entries based on num tile columns minus1 + 1 and num tile rows minus1 + 1. Additionally, the assemble hw pps() function writes a register per tile and indexes the priv tbl->param set[] array using the pic parameter set id. Because these values are derived from an untrusted Picture Parameter Set (PPS), it can lead to out-of-range indexing and writes that exceed hardware table capacities.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97580

Affected Products

Linux Kernel