Improper Validation of Specified Quantity in Input in Linux kernel - CVE-2026-97575
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to improper validation of tile counts in the V4L2 AV1 frame control validation logic when processing V4L2 AV1 frame controls. A local user can submit a crafted control with excessive tile column or row counts to compromise confidentiality, integrity, and availability.