CVE-2026-89724
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: vicodec: fix out-of-bounds write in FWHT encoder
vidioc_s_fmt_vid_out() sizes the encoder CAPTURE buffer from the compressed descriptor pixfmt_fwht, whose sizeimage_mult is 3: coded_w * coded_h * 3 + sizeof(struct fwht_cframe_hdr). fwht_encode_frame() encodes one plane per component, and an incompressible plane takes the FWHT_FRAME_UNENCODED path in encode_plane(), copying the plane verbatim.
For a 4-component pixel format all four planes are full resolution (width_div == height_div == 1), so a frame that forces every plane through the unencoded fallback writes sizeof(struct fwht_cframe_hdr) + 4 * coded_w * coded_h bytes, overrunning the plane by coded_w * coded_h, which can result in corruption of adjacent kernel heap memory.
Bump pixfmt_fwht.sizeimage_mult from 3 to 4, matching the largest components_num among the supported raw formats, so the capture buffer is always large enough for the unencoded fallback.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 16ecf6dff97ce0194a7126e26159492668d47a7e < 84cfebf7f4229d748cca8eb9c4e1f1c4099d3ab7 | affected |
| Linux | Linux | 16ecf6dff97ce0194a7126e26159492668d47a7e < 8c14472431e27f13661d0db9d837156eaced0ecb | affected |
| Linux | Linux | 16ecf6dff97ce0194a7126e26159492668d47a7e < b95315ffc66b39856396c1043618bb4e4d5785ba | affected |
| Linux | Linux | 16ecf6dff97ce0194a7126e26159492668d47a7e < cf4500ebf6fb57bf4ab83c3dd349a40257dbe2a9 | affected |
| Linux | Linux | 5.0 | affected |
| Linux | Linux | 0 < 5.0 | unaffected |
| Linux | Linux | 6.12.109 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.50 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.4 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/84cfebf7f4229d748cca8eb9c4e1f1c4099d3ab7
- https://git.kernel.org/stable/c/8c14472431e27f13661d0db9d837156eaced0ecb
- https://git.kernel.org/stable/c/b95315ffc66b39856396c1043618bb4e4d5785ba
- https://git.kernel.org/stable/c/cf4500ebf6fb57bf4ab83c3dd349a40257dbe2a9
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.