Answer in brief
CVE-2026-97575 records a High severity (CVSS 7.8) vulnerability in media: v4l2-ctrls: validate AV1 tile counts. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=9de30f579980b498606a9c2440b73ae3b670771b <85df9fc79b07f1cc7c953f930ae7e675d0c1e820 || >=9de30f579980b498606a9c2440b73ae3b670771b <c8891da0186fe4c04bccbbd7d84b01a3c941ac7a || >=9de30f579980b498606a9c2440b73ae3b670771b <c4c88b5ba85685043d171e0e9c9d00a8cf6a89e8 || >=9de30f579980b498606a9c2440b73ae3b670771b <439058ced617fbb3febc017b9e93bb7387f309e0 | 85df9fc79b07f1cc7c953f930ae7e675d0c1e820, c8891da0186fe4c04bccbbd7d84b01a3c941ac7a, c4c88b5ba85685043d171e0e9c9d00a8cf6a89e8, 439058ced617fbb3febc017b9e93bb7387f309e0 |
| Linux/Linuxgeneric | 6.5 | Not reported |
Published upstream
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: media: v4l2-ctrls: validate AV1 tile counts The stateless AV1 decoders use tile_info.tile_cols and tile_rows as loop bounds and as indices into the mi_*_starts[] and *_in_sbs_minus_1[] arrays, as the divisor for context_update_tile_id, and their product bounds the per-tile descriptor buffers, but std_validate_compound() does not bound these u8 fields. Reject a V4L2_CTRL_TYPE_AV1_FRAME whose tile_cols or tile_rows exceeds V4L2_AV1_MAX_TILE_COLS / _ROWS, or whose product exceeds V4L2_AV1_MAX_TILE_COUNT. A zero tile count is left to the consuming driver so the zero-initialised control that existing userspace submits is still accepted.
Quoted source text, attributed separately from HOL analysis.