Out-of-bounds write in Linux kernel - CVE-2026-97580
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to out-of-bounds writes in the rkvdec HEVC decoder PPS handling when processing an untrusted HEVC picture parameter set. A local user can provide a picture parameter set with out-of-range tile counts or a picture parameter set identifier to cause memory corruption.