Out-of-bounds write in Linux kernel - CVE-2026-97579
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to an out-of-bounds write in vdec_av1_slice_setup_tile() when processing AV1 bitstream tile information. A local user can provide crafted AV1 tile column or row counts to write beyond the mi_col_starts[] or mi_row_starts[] array capacity and execute arbitrary code.