Description
In the Linux kernel, the following vulnerability has been resolved:

media: rkvdec: hevc: guard INTER_REF_PIC_SET_PRED index underflow

st_ref_pic_set_prediction() computes the reference RPS index as
st_rps_idx - (delta_idx_minus1 + 1) per HEVC spec equation 7-59.
Both operands are u8, so when delta_idx_minus1 + 1 exceeds the
current index the subtraction wraps and the subsequent array access
at calculated_rps_st_sets[ref_rps_idx] reads far out of bounds.

A userspace V4L2 client that can open the RKVDEC m2m decoder can
submit an EXT_SPS_ST_RPS control with INTER_REF_PIC_SET_PRED set
and delta_idx_minus1 crafted to trigger the underflow.

Reject the entry early when the reference index would underflow.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure and potential denial of service
Action: Immediate Patch
AI Analysis

Impact

A flaw in the Linux kernel media driver for RKVDEC HEVC decoding allows an underflow in the calculation of a reference picture set index. When a crafted V4L2 control `EXT_SPS_ST_RPS` is submitted with a large `delta_idx_minus1`, the kernel performs an unsigned 8‑bit subtraction that wraps, causing an out‑of‑bounds read of the picture set array. This can expose kernel memory contents or trigger a crash, leading to information disclosure or denial of service for processes interacting with the driver.

Affected Systems

All Linux kernel installations that include the RKVDEC media driver, regardless of architecture, are potentially affected until the patch that guards the underflow is applied. The CVE does not specify exact kernel versions, so any kernel build prior to the fix is at risk.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity. The EPSS score of less than 1% signals a low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, an attacker with local access to a V4L2 client that can open the RKVDEC m2m decoder could exploit the flaw. Inferred attack vector: a compromised userspace video decoder application leveraging the vulnerable control. The impact may range from a kernel memory disclosure to a service disruption depending on how the out‑of‑bounds data is handled.

Generated by OpenCVE AI on September 18, 2026 at 08:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest kernel update that includes the RKVDEC HEVC guard patch
  • If a kernel update is not immediately available, disable or remove the RKVDEC driver from the system or prevent userspace programs from accessing it
  • Limit or block the EXT_SPS_ST_RPS V4L2 control for V4L2 clients until the fix is applied

Generated by OpenCVE AI on September 18, 2026 at 08:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: rkvdec: hevc: guard INTER_REF_PIC_SET_PRED index underflow st_ref_pic_set_prediction() computes the reference RPS index as st_rps_idx - (delta_idx_minus1 + 1) per HEVC spec equation 7-59. Both operands are u8, so when delta_idx_minus1 + 1 exceeds the current index the subtraction wraps and the subsequent array access at calculated_rps_st_sets[ref_rps_idx] reads far out of bounds. A userspace V4L2 client that can open the RKVDEC m2m decoder can submit an EXT_SPS_ST_RPS control with INTER_REF_PIC_SET_PRED set and delta_idx_minus1 crafted to trigger the underflow. Reject the entry early when the reference index would underflow.
Title media: rkvdec: hevc: guard INTER_REF_PIC_SET_PRED index underflow
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:33.170Z

Reserved: 2026-09-11T19:38:34.772Z

Link: CVE-2026-89882

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:56.647

Modified: 2026-09-16T15:18:14.850

Link: CVE-2026-89882

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:30:06Z

Weaknesses

No weakness.