CVE-2026-97576

Source
https://cve.org/CVERecord?id=CVE-2026-97576
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97576.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-97576
Downstream
Published
2026-09-25T10:21:59Z
Modified
2026-09-26T03:48:29Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
media: v4l2-ctrls: validate HEVC tile counts
Details

In the Linux kernel, the following vulnerability has been resolved:

media: v4l2-ctrls: validate HEVC tile counts

The stateless HEVC decoders read num_tile_columns_minus1 + 1 entries from column_width_minus1[] and num_tile_rows_minus1 + 1 from row_height_minus1[] and use them as tile-loop bounds, but std_validate_compound() does not bound these u8 counts. Reject a V4L2_CTRL_TYPE_HEVC_PPS with tiling enabled whose tile counts exceed the uAPI array capacity, mirroring the existing compound-control range checks.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97576.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
256fa3920874b0f1f4cb79ad6766493a22187153
Fixed
400cd78a63cc647412cf069c9851bdea2818340c
Fixed
c7b1ef6dc57f4e57fe27cfdd3bf82033ed91ca34
Fixed
ba1023d3a6d5d244d59f20c4ba6af4879ae08a9f
Fixed
dc694a9929f7cb9c88ef91e45eb982b7bbe5a477

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97576.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97576.json"