Description
In the Linux kernel, the following vulnerability has been resolved:

media: vicodec: fix out-of-bounds write in FWHT encoder

vidioc_s_fmt_vid_out() sizes the encoder CAPTURE buffer from the
compressed descriptor pixfmt_fwht, whose sizeimage_mult is 3:
coded_w * coded_h * 3 + sizeof(struct fwht_cframe_hdr). fwht_encode_frame()
encodes one plane per component, and an incompressible plane takes the
FWHT_FRAME_UNENCODED path in encode_plane(), copying the plane verbatim.

For a 4-component pixel format all four planes are full resolution
(width_div == height_div == 1), so a frame that forces every plane
through the unencoded fallback writes
sizeof(struct fwht_cframe_hdr) + 4 * coded_w * coded_h bytes, overrunning
the plane by coded_w * coded_h, which can result in corruption
of adjacent kernel heap memory.

Bump pixfmt_fwht.sizeimage_mult from 3 to 4, matching the largest
components_num among the supported raw formats, so the capture buffer is
always large enough for the unencoded fallback.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Heap Corruption via Out-of-Bounds Write
Action: Apply Patch
AI Analysis

Impact

The Linux kernel media/vicodec driver incorrectly calculates capture buffer size for the FWHT encoder. When a four‑component pixel format triggers the unencoded fallback path, the driver writes the encoded frame plus a header into a buffer that is insufficient, resulting in an out‑of‑bounds write. This heap corruption flaw (CWE‑787) could allow an attacker to corrupt the kernel’s memory image, potentially leading to privilege escalation or causing a kernel panic and denial‑of‑service.

Affected Systems

The vulnerability exists in the media/vicodec driver within the Linux kernel, as included in all kernel releases prior to the patch that increases the buffer‑size multiplier to four. Any Linux system that ships the unpatched driver and exposes /dev/video* device nodes is affected. Systems that have updated impacted.

Risk and Exploitability

The CVSS score for this flaw is 7.8, indicating a moderate to high severity, while the EPSS score is below 1%, suggesting a currently low probability of exploitation. The vulnerability is not listed in CISA KEV. The likely attack vector is local: an attacker who can write crafted frames to a /dev/video* device node may trigger the out‑of‑bounds write, corrupt kernel memory, and achieve privilege escalation or denial‑of‑service.

Generated by OpenCVE AI on September 15, 2026 at 20:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel version that includes the FWHT buffer‑ /dev/video* device nodes by assigning them to a trusted group or removing the group privilege limit so only authorized users can open them.
  • Monitor vendor advisories or distribution security channels for updated kernel packages that address the issue.
  • Restrict /dev/video* device node permissions to trusted users or.

Generated by OpenCVE AI on September 15, 2026 at 20:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-122

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-122

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: vicodec: fix out-of-bounds write in FWHT encoder vidioc_s_fmt_vid_out() sizes the encoder CAPTURE buffer from the compressed descriptor pixfmt_fwht, whose sizeimage_mult is 3: coded_w * coded_h * 3 + sizeof(struct fwht_cframe_hdr). fwht_encode_frame() encodes one plane per component, and an incompressible plane takes the FWHT_FRAME_UNENCODED path in encode_plane(), copying the plane verbatim. For a 4-component pixel format all four planes are full resolution (width_div == height_div == 1), so a frame that forces every plane through the unencoded fallback writes sizeof(struct fwht_cframe_hdr) + 4 * coded_w * coded_h bytes, overrunning the plane by coded_w * coded_h, which can result in corruption of adjacent kernel heap memory. Bump pixfmt_fwht.sizeimage_mult from 3 to 4, matching the largest components_num among the supported raw formats, so the capture buffer is always large enough for the unencoded fallback.
Title media: vicodec: fix out-of-bounds write in FWHT encoder
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:02:14.948Z

Reserved: 2026-09-11T19:38:34.759Z

Link: CVE-2026-89724

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:02.050

Modified: 2026-09-14T13:19:21.580

Link: CVE-2026-89724

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:35Z

Links: CVE-2026-89724 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:15:14Z

Weaknesses