SB20260928357 - Improper Validation of Specified Quantity in Input in Linux kernel media v4l2-core driver



SB20260928357 - Improper Validation of Specified Quantity in Input in Linux kernel media v4l2-core driver

Published: September 28, 2026 Updated: September 30, 2026

Security Bulletin ID SB20260928357
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-97575)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper validation of tile counts in the V4L2 AV1 frame control validation logic when processing V4L2 AV1 frame controls. A local user can submit a crafted control with excessive tile column or row counts to compromise confidentiality, integrity, and availability.


Remediation

Install update from vendor's website.