{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89873","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.772Z","datePublished":"2026-09-16T10:31:41.341Z","dateUpdated":"2026-09-16T14:39:28.085Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-16T14:39:28.085Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: v4l2-ctrls: validate HEVC EXT SPS RPS counts\n\nThe HEVC SPS control carries the short-term and long-term RPS counts\nthat decoder drivers use to walk the matching EXT SPS dynamic arrays.\nReject SPS values that exceed the HEVC limits of 64 short-term sets and\n32 long-term references so drivers cannot later index beyond those\ncontrols.\n\nAlso reject EXT SPS ST RPS entries whose negative or positive picture\ncounts exceed the 16-entry arrays, or whose combined delta-POC count\nexceeds the HEVC DPB maximum."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached only through the local V4L2 interface on a stateless HEVC decoder node (/dev/videoN) via VIDIOC_S_EXT_CTRLS plus request-API QBUF/STREAMON. There is no remote or network-facing path into the HEVC SPS or EXT SPS RPS controls.\nAC:L - The attacker supplies num_short_term_ref_pic_sets, num_long_term_ref_pics_sps, num_negative_pics, and num_positive_pics as unconstrained u8 values; any out-of-range count deterministically drives rkvdec HEVC RPS assembly out of bounds on the next decode run. No race, timing window, or uncontrollable memory layout is involved.\nPR:L - Only an unprivileged local account with access to the video device node is required (typically the video group, or the media/codec service on Android and embedded Rockchip devices). rkvdec_open() and rkvdec_hevc_validate_sps() check neither capabilities nor the RPS counts.\nUI:N - The attacking process performs the entire sequence itself: open the decoder, set the crafted HEVC SPS and EXT SPS RPS controls, queue buffers, and start streaming. No victim action, media file, or mount is needed.\nS:U - The out-of-bounds accesses stay inside the kernel's own slab and coherent DMA memory within the same security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - rkvdec_hevc_prepare_hw_st_rps() indexes ext_sps_st_rps[] with an attacker-chosen u8 count up to 255 against a 64-entry (or smaller dynamic) array, and st_ref_pic_set_calculate() reads delta_poc_s0_minus1[] past its 16-entry field, leaking adjacent kernel heap into the decode path.\nI:H - st_ref_pic_set_calculate() writes used_by_curr_pic_s0[]/delta_poc_s0[] with a u8 loop bound up to 255 into 16-entry arrays on a kzalloc object, and rkvdec_set_bw_field() writes RPS bitfields for set index i>63 past the end of the rps DMA object into adjacent priv_tbl memory.\nA:H - The heap overflow of calculated_rps_st_sets and the DMA-table bitfield writes can walk into unmapped or poisoned memory and trip KASAN/hardening checks, producing a kernel oops, and can wedge the decoder hardware; the trigger is repeatable at will."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/media/v4l2-core/v4l2-ctrls-core.c"],"versions":[{"version":"c9a59dc2acc72789d5c778af080d1e65af84862c","lessThan":"30f85a7c59113a8844b276efc010085a34f912e9","status":"affected","versionType":"git"},{"version":"c9a59dc2acc72789d5c778af080d1e65af84862c","lessThan":"796b5c6d4f1615d59d5d8fe5a38fae6bfdfe878e","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/media/v4l2-core/v4l2-ctrls-core.c"],"versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/30f85a7c59113a8844b276efc010085a34f912e9"},{"url":"https://git.kernel.org/stable/c/796b5c6d4f1615d59d5d8fe5a38fae6bfdfe878e"}],"title":"media: v4l2-ctrls: validate HEVC EXT SPS RPS counts","x_generator":{"engine":"bippy-1.2.0"}}}}