CVE-2026-97581

Source
https://cve.org/CVERecord?id=CVE-2026-97581
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97581.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-97581
Downstream
Published
2026-09-25T10:22:02Z
Modified
2026-09-26T03:48:40Z
Summary
media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity
Details

In the Linux kernel, the following vulnerability has been resolved:

media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity

prepare_tile_info_buffer() writes one entry per tile into the tile_sizes DMA buffer, sized for a grid equal to the PPS uAPI array capacity. Use the bounded v4l2_hevc_pps_num_tile_columns() / v4l2_hevc_pps_num_tile_rows() helpers so the loops stay inside the buffer.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97581.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
cb5dd5a0fa518dff14ff2b90837c3c8f98f4dd5c
Fixed
62ae24639d22909a5724627a0467e4bde9704020
Fixed
4f654c9bc954569ff9b8ab860b29480c4cf6f57b
Fixed
05e8e4cdfe692f5cedba9aa9d7b8f2584cf926c8
Fixed
06236b094c899c22c12ac5097935eb6719293de8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97581.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.14.0
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97581.json"