Description
In the Linux kernel, the following vulnerability has been resolved:

media: v4l2-ctrls: validate HEVC EXT SPS RPS counts

The HEVC SPS control carries the short-term and long-term RPS counts
that decoder drivers use to walk the matching EXT SPS dynamic arrays.
Reject SPS values that exceed the HEVC limits of 64 short-term sets and
32 long-term references so drivers cannot later index beyond those
controls.

Also reject EXT SPS ST RPS entries whose negative or positive picture
counts exceed the 16-entry arrays, or whose combined delta-POC count
exceeds the HEVC DPB maximum.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds array access potentially leading to kernel crash or arbitrary code execution
Action: Patch
AI Analysis

Impact

The Linux kernel media subsystem’s v4l2‑ctrls component lacked validation for the HEVC Sequence Parameter Set (SPS) control values that specify short‑term and long‑term Reference Picture Set counts. When the counts supplied by an attacker exceed the HEVC limits—64 short‑term sets, 32 long‑term references—or when extended SPS entries contain picture counts outside the 16‑entry arrays or combined delta‑POC values beyond the Decoding Picture Buffer maximum, drivers can index beyond the bounds of internal control arrays. The resulting memory corruption could cause a kernel crash or, in some execution contexts, arbitrary code execution with kernel privileges. This vulnerability is therefore a classic buffer control flaw that directly endangers system integrity.

Affected Systems

Every Linux kernel that incorporates the unpatched v4l2‑ctrls media component is affected. The CNA identifies only the kernel itself as the product, with no version range specified, which implies that any installation lacking the validation logic is vulnerable. Devices that use the media driver—such as webcams, media players, or embedded video adapters that accept externally supplied HEVC streams—are at risk, as they rely on the kernel to process those streams.

Risk and Exploitability

The CVSS score of 7.8 classifies the flaw as high severity. The EPSS score is listed as <1%, indicating a very low calculated likelihood of exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker must supply a malicious HEVC stream containing malformed SPS values to the kernel’s media subsystem; the likely attack vector is through compromised cameras, infected media files, or other external media sources processed by media drivers. The low EPSS does not eliminate the risk, especially in environments that frequently process untrusted video input.

Generated by OpenCVE AI on September 18, 2026 at 09:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that includes the patched v4l2‑ctrls code that validates HEVC SPS counts
  • If an immediate kernel upgrade is not possible, disable HEVC decoding or configure the media subsystem to reject any HEVC streams that violate the strict HEVC limits, preventing malformed streams from being processed
  • Verify that any firmware or hardware delivering HEVC data to the kernel is trusted, keep media processing applications up to date, and consider sandboxing or restricting external media sources to limit attacker control of HEVC payloads

Generated by OpenCVE AI on September 18, 2026 at 09:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-787

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: v4l2-ctrls: validate HEVC EXT SPS RPS counts The HEVC SPS control carries the short-term and long-term RPS counts that decoder drivers use to walk the matching EXT SPS dynamic arrays. Reject SPS values that exceed the HEVC limits of 64 short-term sets and 32 long-term references so drivers cannot later index beyond those controls. Also reject EXT SPS ST RPS entries whose negative or positive picture counts exceed the 16-entry arrays, or whose combined delta-POC count exceeds the HEVC DPB maximum.
Title media: v4l2-ctrls: validate HEVC EXT SPS RPS counts
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:28.085Z

Reserved: 2026-09-11T19:38:34.772Z

Link: CVE-2026-89873

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:55.540

Modified: 2026-09-16T15:18:14.330

Link: CVE-2026-89873

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:30:06Z

Weaknesses