CVE-2026-97579

Source
https://cve.org/CVERecord?id=CVE-2026-97579
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97579.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-97579
Downstream
Published
2026-09-25T10:22:01Z
Modified
2026-09-26T03:48:40Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
media: mediatek: vcodec: bound AV1 tile-start copy to the array capacity
Details

In the Linux kernel, the following vulnerability has been resolved:

media: mediatek: vcodec: bound AV1 tile-start copy to the array capacity

vdec_av1_slice_setup_tile() copies tile_cols + 1 / tile_rows + 1 entries into mi_col_starts[] / mi_row_starts[] from the bitstream tile_info. Bound the copy to the array capacity.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97579.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0934d37596151edce115c6d0843a9ad7d5e5d232
Fixed
ad47a250afafa3a51cfb4a004463ff28e66c596e
Fixed
7992059c045780095ba5a696dcb2f5400a82803c
Fixed
eb0ea3898e3921900939e30c3946dd2b52281859
Fixed
37bef2170d4c88fc3d708eecf3ef0f4032bc1372

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97579.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.6.0
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97579.json"