Improper Validation of Specified Quantity in Input in Linux kernel - CVE-2026-97575

 

Improper Validation of Specified Quantity in Input in Linux kernel - CVE-2026-97575

Published: September 28, 2026


Vulnerability identifier: #VU152628
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-97575
CWE-ID: CWE-1284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper validation of tile counts in the V4L2 AV1 frame control validation logic when processing V4L2 AV1 frame controls. A local user can submit a crafted control with excessive tile column or row counts to compromise confidentiality, integrity, and availability.


Affected software

Linux kernel

How to mitigate CVE-2026-97575

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins