{"id":"CVE-2026-93236","published":"2026-09-24T16:17:19.297","lastModified":"2026-09-24T16:17:19.297","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common\n\nWhen VIDIOC_TRY_FMT is called with an unsupported pixel format on the\nOUTPUT queue, vdec_try_fmt_common() falls back to V4L2_PIX_FMT_MPEG2.\nHowever, if a distro has locally patched MPEG2 support out (as it has\nbeen broken for some time) the platform format table does not contain\nMPEG2 so find_format() returns NULL and the subsequent dereference of\nfmt_out->max_width triggers a NULL pointer dereference.\n\nFix this by falling back to the first format in the platform's format\narray instead of hardcoding V4L2_PIX_FMT_MPEG2. This is always valid\nsince every platform defines at least one format.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/20aa934ace6917262ff579a73ec018d06a7bad1c","tags":[]},{"url":"https://git.kernel.org/stable/c/276f28672bb6d5d5feca78db4219c7b5adf1be26","tags":[]},{"url":"https://git.kernel.org/stable/c/3839b6be2279fc4f558723f2c0fbfc9c42070958","tags":[]},{"url":"https://git.kernel.org/stable/c/680a89683197cdfe4e03e6fd7755454c647d39c1","tags":[]},{"url":"https://git.kernel.org/stable/c/96dafbae77f50bfe2228bcfedcd8652c5e5f08e8","tags":[]},{"url":"https://git.kernel.org/stable/c/c620906fb1b2ad75d408ea9d06040d66952d4a31","tags":[]},{"url":"https://git.kernel.org/stable/c/d61ba609c3226af3c84268ba606ea06ee63e511b","tags":[]},{"url":"https://git.kernel.org/stable/c/f2375a308640e401c142c5426d52c3d10e016d25","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}