Improper Initialization in Linux kernel - CVE-2026-43235
Published: May 7, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper initialization in platform data handling in the media: iris driver when bringing up decode or encode sessions on SM8750. A local user can trigger session initialization to cause a denial of service.
The issue can lead to basic decode or encode failures, and encoder capability checks may be incomplete.