« Volver al listado

CVE-2026-89724

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

media: vicodec: fix out-of-bounds write in FWHT encoder

vidioc_s_fmt_vid_out() sizes the encoder CAPTURE buffer from the compressed descriptor pixfmt_fwht, whose sizeimage_mult is 3: coded_w * coded_h * 3 + sizeof(struct fwht_cframe_hdr). fwht_encode_frame() encodes one plane per component, and an incompressible plane takes the FWHT_FRAME_UNENCODED path in encode_plane(), copying the plane verbatim.

For a 4-component pixel format all four planes are full resolution (width_div == height_div == 1), so a frame that forces every plane through the unencoded fallback writes sizeof(struct fwht_cframe_hdr) + 4 * coded_w * coded_h bytes, overrunning the plane by coded_w * coded_h, which can result in corruption of adjacent kernel heap memory.

Leer descripción completaMostrar menos

Bump pixfmt_fwht.sizeimage_mult from 3 to 4, matching the largest components_num among the supported raw formats, so the capture buffer is always large enough for the unencoded fallback.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de escritura fuera de límites en kernel local (AV:L, PR:L, UI:N). Impactos: corrupción de memoria heap adyacente (T1565.001) y potencial denegación de servicio (T1499.004).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89724",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "16ecf6dff97ce0194a7126e26159492668d47a7e",
              "lessThan": "f7ae26c100a6c26c2a166d2c41e73188067b36bd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "16ecf6dff97ce0194a7126e26159492668d47a7e",
              "lessThan": "6ea647e76c44387d5c1c635df4604c2154d9060e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "16ecf6dff97ce0194a7126e26159492668d47a7e",
              "lessThan": "d40838a63f2bd6a3df0a6cdd8ff1d5c6366e8fff",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "16ecf6dff97ce0194a7126e26159492668d47a7e",
              "lessThan": "e21cccc29b840930cd9dcfdf1139658063a681af",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "16ecf6dff97ce0194a7126e26159492668d47a7e",
              "lessThan": "84cfebf7f4229d748cca8eb9c4e1f1c4099d3ab7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "16ecf6dff97ce0194a7126e26159492668d47a7e",
              "lessThan": "8c14472431e27f13661d0db9d837156eaced0ecb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "16ecf6dff97ce0194a7126e26159492668d47a7e",
              "lessThan": "b95315ffc66b39856396c1043618bb4e4d5785ba",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "16ecf6dff97ce0194a7126e26159492668d47a7e",
              "lessThan": "cf4500ebf6fb57bf4ab83c3dd349a40257dbe2a9",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/media/test-drivers/vicodec/vicodec-core.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.270",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.109",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.50",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/media/test-drivers/vicodec/vicodec-core.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:20:02.050",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/6ea647e76c44387d5c1c635df4604c2154d9060e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/84cfebf7f4229d748cca8eb9c4e1f1c4099d3ab7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8c14472431e27f13661d0db9d837156eaced0ecb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b95315ffc66b39856396c1043618bb4e4d5785ba",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cf4500ebf6fb57bf4ab83c3dd349a40257dbe2a9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d40838a63f2bd6a3df0a6cdd8ff1d5c6366e8fff",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e21cccc29b840930cd9dcfdf1139658063a681af",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f7ae26c100a6c26c2a166d2c41e73188067b36bd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: vicodec: fix out-of-bounds write in FWHT encoder\n\nvidioc_s_fmt_vid_out() sizes the encoder CAPTURE buffer from the\ncompressed descriptor pixfmt_fwht, whose sizeimage_mult is 3:\ncoded_w * coded_h * 3 + sizeof(struct fwht_cframe_hdr). fwht_encode_frame()\nencodes one plane per component, and an incompressible plane takes the\nFWHT_FRAME_UNENCODED path in encode_plane(), copying the plane verbatim.\n\nFor a 4-component pixel format all four planes are full resolution\n(width_div == height_div == 1), so a frame that forces every plane\nthrough the unencoded fallback writes\nsizeof(struct fwht_cframe_hdr) + 4 * coded_w * coded_h bytes, overrunning\nthe plane by coded_w * coded_h, which can result in corruption\nof adjacent kernel heap memory.\n\nBump pixfmt_fwht.sizeimage_mult from 3 to 4, matching the largest\ncomponents_num among the supported raw formats, so the capture buffer is\nalways large enough for the unencoded fallback."
    }
  ],
  "lastModified": "2026-09-14T13:19:21.580",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}