{"id":"CVE-2026-97580","published":"2026-09-25T11:17:08.790","lastModified":"2026-09-25T15:18:00.170","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: rkvdec: bound HEVC tile loops and PPS id to the array capacity\n\ncompute_tiles_uniform() and compute_tiles_non_uniform() loop over\nnum_tile_columns_minus1 + 1 / num_tile_rows_minus1 + 1 entries, and\nassemble_hw_pps() writes one COLUMN_WIDTH / ROW_HEIGHT register per tile\nand indexes priv_tbl->param_set[] by pic_parameter_set_id, all taken from\nthe untrusted PPS. Use the bounded v4l2_hevc_pps_num_tile_columns() /\nv4l2_hevc_pps_num_tile_rows() helpers for the tile loops, and bail out of\nassemble_hw_pps() before indexing priv_tbl->param_set[] with an\nout-of-range pic_parameter_set_id, so the writes stay within the hardware\ntables.","cvssScore":7.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/03beb248d8a7bab30559a60d4df81f167e63b9e3","tags":[]},{"url":"https://git.kernel.org/stable/c/81ad46bb33d8fd279aaa33af5296c648814c964b","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}