๐Ÿ” CVE Alert

CVE-2026-97576

UNKNOWN 0.0

media: v4l2-ctrls: validate HEVC tile counts

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: media: v4l2-ctrls: validate HEVC tile counts The stateless HEVC decoders read num_tile_columns_minus1 + 1 entries from column_width_minus1[] and num_tile_rows_minus1 + 1 from row_height_minus1[] and use them as tile-loop bounds, but std_validate_compound() does not bound these u8 counts. Reject a V4L2_CTRL_TYPE_HEVC_PPS with tiling enabled whose tile counts exceed the uAPI array capacity, mirroring the existing compound-control range checks.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
256fa3920874b0f1f4cb79ad6766493a22187153 < 400cd78a63cc647412cf069c9851bdea2818340c 256fa3920874b0f1f4cb79ad6766493a22187153 < c7b1ef6dc57f4e57fe27cfdd3bf82033ed91ca34 256fa3920874b0f1f4cb79ad6766493a22187153 < ba1023d3a6d5d244d59f20c4ba6af4879ae08a9f 256fa3920874b0f1f4cb79ad6766493a22187153 < dc694a9929f7cb9c88ef91e45eb982b7bbe5a477
Linux / Linux
5.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/400cd78a63cc647412cf069c9851bdea2818340c git.kernel.org: https://git.kernel.org/stable/c/c7b1ef6dc57f4e57fe27cfdd3bf82033ed91ca34 git.kernel.org: https://git.kernel.org/stable/c/ba1023d3a6d5d244d59f20c4ba6af4879ae08a9f git.kernel.org: https://git.kernel.org/stable/c/dc694a9929f7cb9c88ef91e45eb982b7bbe5a477