Memory corruption in Linux kernel - CVE-2026-89873
Published: September 17, 2026
Vulnerability details
The vulnerability allows a local user to cause an out-of-bounds access.
The vulnerability exists due to improper bounds checking in V4L2 HEVC SPS and EXT SPS RPS control validation when processing user-supplied HEVC controls. A local user can submit controls with excessive reference picture set or picture counts to cause an out-of-bounds access.