Impact
The Linux kernel media subsystem’s v4l2‑ctrls component lacked validation for the HEVC Sequence Parameter Set (SPS) control values that specify short‑term and long‑term Reference Picture Set counts. When the counts supplied by an attacker exceed the HEVC limits—64 short‑term sets, 32 long‑term references—or when extended SPS entries contain picture counts outside the 16‑entry arrays or combined delta‑POC values beyond the Decoding Picture Buffer maximum, drivers can index beyond the bounds of internal control arrays. The resulting memory corruption could cause a kernel crash or, in some execution contexts, arbitrary code execution with kernel privileges. This vulnerability is therefore a classic buffer control flaw that directly endangers system integrity.
Affected Systems
Every Linux kernel that incorporates the unpatched v4l2‑ctrls media component is affected. The CNA identifies only the kernel itself as the product, with no version range specified, which implies that any installation lacking the validation logic is vulnerable. Devices that use the media driver—such as webcams, media players, or embedded video adapters that accept externally supplied HEVC streams—are at risk, as they rely on the kernel to process those streams.
Risk and Exploitability
The CVSS score of 7.8 classifies the flaw as high severity. The EPSS score is listed as <1%, indicating a very low calculated likelihood of exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker must supply a malicious HEVC stream containing malformed SPS values to the kernel’s media subsystem; the likely attack vector is through compromised cameras, infected media files, or other external media sources processed by media drivers. The low EPSS does not eliminate the risk, especially in environments that frequently process untrusted video input.
OpenCVE Enrichment