SB20260928357 - Improper Validation of Specified Quantity in Input in Linux kernel media v4l2-core driver
Published: September 28, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-97575)
CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to improper validation of tile counts in the V4L2 AV1 frame control validation logic when processing V4L2 AV1 frame controls. A local user can submit a crafted control with excessive tile column or row counts to compromise confidentiality, integrity, and availability.
Remediation
Install update from vendor's website.