CVE-2026-97575

Source
https://cve.org/CVERecord?id=CVE-2026-97575
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97575.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-97575
Downstream
Published
2026-09-25T10:21:58Z
Modified
2026-09-26T03:48:35Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
media: v4l2-ctrls: validate AV1 tile counts
Details

In the Linux kernel, the following vulnerability has been resolved:

media: v4l2-ctrls: validate AV1 tile counts

The stateless AV1 decoders use tile_info.tile_cols and tile_rows as loop bounds and as indices into the mi_*_starts[] and *_in_sbs_minus_1[] arrays, as the divisor for context_update_tile_id, and their product bounds the per-tile descriptor buffers, but std_validate_compound() does not bound these u8 fields. Reject a V4L2_CTRL_TYPE_AV1_FRAME whose tile_cols or tile_rows exceeds V4L2_AV1_MAX_TILE_COLS / _ROWS, or whose product exceeds V4L2_AV1_MAX_TILE_COUNT. A zero tile count is left to the consuming driver so the zero-initialised control that existing userspace submits is still accepted.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97575.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9de30f579980b498606a9c2440b73ae3b670771b
Fixed
85df9fc79b07f1cc7c953f930ae7e675d0c1e820
Fixed
c8891da0186fe4c04bccbbd7d84b01a3c941ac7a
Fixed
c4c88b5ba85685043d171e0e9c9d00a8cf6a89e8
Fixed
439058ced617fbb3febc017b9e93bb7387f309e0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97575.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.5.0
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97575.json"