Impact
A flaw in the Linux kernel media driver for RKVDEC HEVC decoding allows an underflow in the calculation of a reference picture set index. When a crafted V4L2 control `EXT_SPS_ST_RPS` is submitted with a large `delta_idx_minus1`, the kernel performs an unsigned 8‑bit subtraction that wraps, causing an out‑of‑bounds read of the picture set array. This can expose kernel memory contents or trigger a crash, leading to information disclosure or denial of service for processes interacting with the driver.
Affected Systems
All Linux kernel installations that include the RKVDEC media driver, regardless of architecture, are potentially affected until the patch that guards the underflow is applied. The CVE does not specify exact kernel versions, so any kernel build prior to the fix is at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score of less than 1% signals a low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, an attacker with local access to a V4L2 client that can open the RKVDEC m2m decoder could exploit the flaw. Inferred attack vector: a compromised userspace video decoder application leveraging the vulnerable control. The impact may range from a kernel memory disclosure to a service disruption depending on how the out‑of‑bounds data is handled.
OpenCVE Enrichment