Out-of-bounds read in Linux kernel - CVE-2026-97576
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to an out-of-bounds read in stateless HEVC decoder tile processing when processing a V4L2 HEVC PPS control with excessive tile counts. A local user can submit a crafted HEVC PPS control to compromise confidentiality, integrity, and availability.