In the Linux kernel, the following vulnerability has been resolved:
media: cedrus: skip invalid H.264 reference list entries
Cedrus consumes H.264 refpiclist0/refpiclist1 entries from the stateless slice control and later uses their indices to look up decode->dpb[] in cedruswritereflist().
Rejecting such controls in cedrustryctrl() would break existing userspace, since stateless H.264 reference lists may legitimately carry out-of-range indices for missing references. Instead, guard the actual DPB lookup in Cedrus and skip entries whose indices do not fit the fixed V4L2H264NUMDPBENTRIES array.
This keeps the fix local to the driver use site and avoids out-of-bounds reads from malformed or unsupported reference list entries.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68229.json",
"cna_assigner": "Linux"
}