๐Ÿ” CVE Alert

CVE-2026-97575

UNKNOWN 0.0

media: v4l2-ctrls: validate AV1 tile counts

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: media: v4l2-ctrls: validate AV1 tile counts The stateless AV1 decoders use tile_info.tile_cols and tile_rows as loop bounds and as indices into the mi_*_starts[] and *_in_sbs_minus_1[] arrays, as the divisor for context_update_tile_id, and their product bounds the per-tile descriptor buffers, but std_validate_compound() does not bound these u8 fields. Reject a V4L2_CTRL_TYPE_AV1_FRAME whose tile_cols or tile_rows exceeds V4L2_AV1_MAX_TILE_COLS / _ROWS, or whose product exceeds V4L2_AV1_MAX_TILE_COUNT. A zero tile count is left to the consuming driver so the zero-initialised control that existing userspace submits is still accepted.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
9de30f579980b498606a9c2440b73ae3b670771b < 85df9fc79b07f1cc7c953f930ae7e675d0c1e820 9de30f579980b498606a9c2440b73ae3b670771b < c8891da0186fe4c04bccbbd7d84b01a3c941ac7a 9de30f579980b498606a9c2440b73ae3b670771b < c4c88b5ba85685043d171e0e9c9d00a8cf6a89e8 9de30f579980b498606a9c2440b73ae3b670771b < 439058ced617fbb3febc017b9e93bb7387f309e0
Linux / Linux
6.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/85df9fc79b07f1cc7c953f930ae7e675d0c1e820 git.kernel.org: https://git.kernel.org/stable/c/c8891da0186fe4c04bccbbd7d84b01a3c941ac7a git.kernel.org: https://git.kernel.org/stable/c/c4c88b5ba85685043d171e0e9c9d00a8cf6a89e8 git.kernel.org: https://git.kernel.org/stable/c/439058ced617fbb3febc017b9e93bb7387f309e0