{"api_version":"1","generated_at":"2026-10-01T09:08:37+00:00","cve":"CVE-2026-97579","urls":{"html":"https://cve.report/CVE-2026-97579","api":"https://cve.report/api/cve/CVE-2026-97579.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-97579","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-97579"},"summary":{"title":"media: mediatek: vcodec: bound AV1 tile-start copy to the array capacity","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: mediatek: vcodec: bound AV1 tile-start copy to the array capacity\n\nvdec_av1_slice_setup_tile() copies tile_cols + 1 / tile_rows + 1 entries\ninto mi_col_starts[] / mi_row_starts[] from the bitstream tile_info. Bound\nthe copy to the array capacity.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-25 11:17:08","updated_at":"2026-09-25 15:18:00"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/ad47a250afafa3a51cfb4a004463ff28e66c596e","name":"https://git.kernel.org/stable/c/ad47a250afafa3a51cfb4a004463ff28e66c596e","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/7992059c045780095ba5a696dcb2f5400a82803c","name":"https://git.kernel.org/stable/c/7992059c045780095ba5a696dcb2f5400a82803c","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/eb0ea3898e3921900939e30c3946dd2b52281859","name":"https://git.kernel.org/stable/c/eb0ea3898e3921900939e30c3946dd2b52281859","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/37bef2170d4c88fc3d708eecf3ef0f4032bc1372","name":"https://git.kernel.org/stable/c/37bef2170d4c88fc3d708eecf3ef0f4032bc1372","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-97579","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97579","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0934d37596151edce115c6d0843a9ad7d5e5d232 ad47a250afafa3a51cfb4a004463ff28e66c596e git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0934d37596151edce115c6d0843a9ad7d5e5d232 7992059c045780095ba5a696dcb2f5400a82803c git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0934d37596151edce115c6d0843a9ad7d5e5d232 eb0ea3898e3921900939e30c3946dd2b52281859 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0934d37596151edce115c6d0843a9ad7d5e5d232 37bef2170d4c88fc3d708eecf3ef0f4032bc1372 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.6","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.111 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.53 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.7 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc3 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"97579","cve":"CVE-2026-97579","epss":"0.001630000","percentile":"0.049130000","score_date":"2026-09-27","updated_at":"2026-09-28 00:02:23"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/media/platform/mediatek/vcodec/decoder/vdec/vdec_av1_req_lat_if.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"ad47a250afafa3a51cfb4a004463ff28e66c596e","status":"affected","version":"0934d37596151edce115c6d0843a9ad7d5e5d232","versionType":"git"},{"lessThan":"7992059c045780095ba5a696dcb2f5400a82803c","status":"affected","version":"0934d37596151edce115c6d0843a9ad7d5e5d232","versionType":"git"},{"lessThan":"eb0ea3898e3921900939e30c3946dd2b52281859","status":"affected","version":"0934d37596151edce115c6d0843a9ad7d5e5d232","versionType":"git"},{"lessThan":"37bef2170d4c88fc3d708eecf3ef0f4032bc1372","status":"affected","version":"0934d37596151edce115c6d0843a9ad7d5e5d232","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/media/platform/mediatek/vcodec/decoder/vdec/vdec_av1_req_lat_if.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.6"},{"lessThan":"6.6","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.111","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.53","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.7","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc3","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.111","versionStartIncluding":"6.6","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.53","versionStartIncluding":"6.6","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.7","versionStartIncluding":"6.6","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc3","versionStartIncluding":"6.6","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: mediatek: vcodec: bound AV1 tile-start copy to the array capacity\n\nvdec_av1_slice_setup_tile() copies tile_cols + 1 / tile_rows + 1 entries\ninto mi_col_starts[] / mi_row_starts[] from the bitstream tile_info. Bound\nthe copy to the array capacity."}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The bad tile_info.tile_cols/tile_rows reach vdec_av1_slice_setup_tile() from a local process that sets V4L2_CID_STATELESS_AV1_FRAME via VIDIOC_S_EXT_CTRLS on the mtk-vcodec decoder /dev/videoN and queues a request. A spec-conforming AV1 parser caps tile counts at 64, so a remote bitstream does not produce the malformed values.\nAC:L - The attacker sets tile_cols or tile_rows to any value from 65 to 255. validate_av1_frame() never checks them, and the driver's num_tiles check in vdec_av1_slice_setup_tile_group() runs after vdec_av1_slice_setup_pfc() has already done the copy, so the overflow happens on every such request.\nPR:L - It needs only the ability to open the decoder video node, which is normally granted to the video group or to media/GPU processes. No capability check lies on the ioctl or request-queue path to vdec_av1_slice_lat_decode().\nUI:N - The attacker supplies the control payload and queues the request themselves. No other user has to do anything.\nS:U - This is a heap overflow in kernel memory. It gives kernel-level impact within the same security authority, not a VM or IOMMU boundary crossing.\nC:H - Writing up to 764 bytes past mi_row_starts[] runs off the end of the kzalloc'd vdec_av1_slice_pfc into the neighbouring slab object. That corruption can be used to build read primitives and leak kernel memory.\nI:H - The written values are ALIGN(ctrl_tile->mi_*_starts[i]) >> mib_size_log2, taken from the attacker's own control payload. This gives an attacker-shaped heap out-of-bounds write that can corrupt neighbouring objects.\nA:H - Corrupting the pfc fields past the tile arrays (frame, state, ref_idx) and the neighbouring slab object can oops the kernel or hang the decoder, and any local user with device access can repeat it."}]}],"providerMetadata":{"dateUpdated":"2026-09-25T14:41:22.453Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/ad47a250afafa3a51cfb4a004463ff28e66c596e"},{"url":"https://git.kernel.org/stable/c/7992059c045780095ba5a696dcb2f5400a82803c"},{"url":"https://git.kernel.org/stable/c/eb0ea3898e3921900939e30c3946dd2b52281859"},{"url":"https://git.kernel.org/stable/c/37bef2170d4c88fc3d708eecf3ef0f4032bc1372"}],"title":"media: mediatek: vcodec: bound AV1 tile-start copy to the array capacity","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-97579","datePublished":"2026-09-25T10:22:01.216Z","dateReserved":"2026-09-24T16:01:01.156Z","dateUpdated":"2026-09-25T14:41:22.453Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-25 11:17:08","lastModifiedDate":"2026-09-25 15:18:00","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"97579","Ordinal":"1","Title":"media: mediatek: vcodec: bound AV1 tile-start copy to the array ","CVE":"CVE-2026-97579","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"97579","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: mediatek: vcodec: bound AV1 tile-start copy to the array capacity\n\nvdec_av1_slice_setup_tile() copies tile_cols + 1 / tile_rows + 1 entries\ninto mi_col_starts[] / mi_row_starts[] from the bitstream tile_info. Bound\nthe copy to the array capacity.","Type":"Description","Title":"media: mediatek: vcodec: bound AV1 tile-start copy to the array "}]}}}