Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-97581— media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: 媒体子系统:verisilicon: hantro: 将 G2 HEVC 图块循环限制在缓冲区容量范围内 prepare_tile_info_buffer() 函数会将每个图块对应的一条信息写入 tile_sizes DMA 缓冲区,该缓冲区的大小是根据 PPS 用户空间接口(uAPI)数组容量所定义的网格来分配的。为此,引入使用 v4l2_hevc_pps_num_tile_columns() 和 v4l2_hevc_pps_num_tile_rows() 这两个辅助函数

AI Predicted 7.8 Difficulty: Easy EPSS 0.21% · P10

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 14

VendorProduct Version RangeStatus
Linux Linux cb5dd5a0fa518dff14ff2b90837c3c8f98f4dd5c< 6d192fc0d6faff25ecf6d52cbde4b939cb12c192 affected
cb5dd5a0fa518dff14ff2b90837c3c8f98f4dd5c< 2887a98c03d97a6fcb6c2dab92956f2f4c402cdd affected
cb5dd5a0fa518dff14ff2b90837c3c8f98f4dd5c< 62ae24639d22909a5724627a0467e4bde9704020 affected
cb5dd5a0fa518dff14ff2b90837c3c8f98f4dd5c< 4f654c9bc954569ff9b8ab860b29480c4cf6f57b affected
cb5dd5a0fa518dff14ff2b90837c3c8f98f4dd5c< 05e8e4cdfe692f5cedba9aa9d7b8f2584cf926c8 affected
cb5dd5a0fa518dff14ff2b90837c3c8f98f4dd5c< 06236b094c899c22c12ac5097935eb6719293de8 affected
5.14 affected
< 5.14 unaffected
… +6 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-97581

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity prepare_tile_info_buffer() writes one entry per tile into the tile_sizes DMA buffer, sized for a grid equal to the PPS uAPI array capacity. Use the bounded v4l2_hevc_pps_num_tile_columns() / v4l2_hevc_pps_num_tile_rows() helpers so the loops stay inside the buffer.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux cb5dd5a0fa518dff14ff2b90837c3c8f98f4dd5c ~ 6d192fc0d6faff25ecf6d52cbde4b939cb12c192 -
Linux Linux 5.14 -

II. Public POCs for CVE-2026-97581

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-97581

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-97581 (6)

Same Patch Batch · Linux · 2026-09-25 · 372 CVEs total

CVE-2026-100075 9.8 CRITICAL RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters
CVE-2026-97957 8.8 HIGH net: hinic: fix mailbox segment buffer overflow
CVE-2026-97527 8.8 HIGH scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock
CVE-2026-97528 8.8 HIGH scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error
CVE-2026-97555 8.8 HIGH smb: client: fix heap overflow in DACL owner/group rewrite
CVE-2026-98115 8.8 HIGH ksmbd: safely drain sessions during logoff
CVE-2026-97525 8.2 HIGH x86/mm/pat: Allocate split page tables as kernel page tables
CVE-2026-97573 8.1 HIGH bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset()
CVE-2026-97570 8.1 HIGH bnxt_en: Bound SW TPA IDs to prevent crashes
CVE-2026-98070 8.1 HIGH net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks()
CVE-2026-98069 8.1 HIGH net/rds: acquire the fastpath locks in rds_conn_shutdown()
CVE-2026-98130 8.1 HIGH sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START
CVE-2026-98116 7.8 HIGH ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF
CVE-2026-97903 7.8 HIGH exit: hold a reference to thread_pid across proc_flush_pid
CVE-2026-97548 7.8 HIGH xfs: fix the rtrmap and rtrefcount _maxlevels_ondisk functions
CVE-2026-97611 7.8 HIGH net: openvswitch: fix use-after-free of the flow table mask array
CVE-2026-97612 7.8 HIGH net: mpls: clear inner_protocol when the last label is popped
CVE-2026-98073 7.8 HIGH net: Remove conflicting altnames for dying netns in __dev_change_net_namespace().
CVE-2026-97602 7.8 HIGH inet: frags: invalidate queues before flushing them
CVE-2026-97577 7.8 HIGH media: verisilicon: rockchip: reject AV1 frames exceeding the tile capacity

Showing top 20 of 372 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-97581

No comments yet


Leave a comment