CVE-2026-93236

Source
https://cve.org/CVERecord?id=CVE-2026-93236
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93236.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93236
Downstream
Published
2026-09-24T15:33:35Z
Modified
2026-09-25T03:48:54Z
Summary
media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common
Details

In the Linux kernel, the following vulnerability has been resolved:

media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common

When VIDIOC_TRY_FMT is called with an unsupported pixel format on the OUTPUT queue, vdec_try_fmt_common() falls back to V4L2_PIX_FMT_MPEG2. However, if a distro has locally patched MPEG2 support out (as it has been broken for some time) the platform format table does not contain MPEG2 so find_format() returns NULL and the subsequent dereference of fmt_out->max_width triggers a NULL pointer dereference.

Fix this by falling back to the first format in the platform's format array instead of hardcoding V4L2_PIX_FMT_MPEG2. This is always valid since every platform defines at least one format.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93236.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3e7f51bd96077acad6acd7b45668f65b44233c4e
Fixed
276f28672bb6d5d5feca78db4219c7b5adf1be26
Fixed
c620906fb1b2ad75d408ea9d06040d66952d4a31
Fixed
3839b6be2279fc4f558723f2c0fbfc9c42070958
Fixed
680a89683197cdfe4e03e6fd7755454c647d39c1
Fixed
f2375a308640e401c142c5426d52c3d10e016d25
Fixed
96dafbae77f50bfe2228bcfedcd8652c5e5f08e8
Fixed
d61ba609c3226af3c84268ba606ea06ee63e511b
Fixed
20aa934ace6917262ff579a73ec018d06a7bad1c

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93236.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.3.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93236.json"