Out-of-bounds read in Linux kernel - CVE-2026-97577
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to perform out-of-bounds memory reads and writes.
The vulnerability exists due to improper bounds checking in rockchip_vpu981_av1_dec_prepare_run() and rockchip_vpu981_av1_dec_set_tile_info() when processing AV1 frames whose claimed tile count exceeds the submitted tile group entry count or the tile descriptor buffer capacity. A local user can submit a crafted AV1 frame with excessive tile dimensions to perform out-of-bounds memory reads and writes.