« Volver al listado

CVE-2026-89882

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

media: rkvdec: hevc: guard INTER_REF_PIC_SET_PRED index underflow

st_ref_pic_set_prediction() computes the reference RPS index as st_rps_idx - (delta_idx_minus1 + 1) per HEVC spec equation 7-59. Both operands are u8, so when delta_idx_minus1 + 1 exceeds the current index the subtraction wraps and the subsequent array access at calculated_rps_st_sets[ref_rps_idx] reads far out of bounds.

A userspace V4L2 client that can open the RKVDEC m2m decoder can submit an EXT_SPS_ST_RPS control with INTER_REF_PIC_SET_PRED set and delta_idx_minus1 crafted to trigger the underflow.

Leer descripción completaMostrar menos

Reject the entry early when the reference index would underflow.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local (AV:L/PR:L) en kernel que permite lectura fuera de límites mediante control V4L2 mal validado; escalada acceso a memoria kernel.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89882",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "c9a59dc2acc72789d5c778af080d1e65af84862c",
              "lessThan": "74938f83a8abbee8f502dfb5d94213b2497d1edf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c9a59dc2acc72789d5c778af080d1e65af84862c",
              "lessThan": "052c5ed5a1d96a6b24fd50ccda16fc6841ee7ca3",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/media/platform/rockchip/rkvdec/rkvdec-hevc-common.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/media/platform/rockchip/rkvdec/rkvdec-hevc-common.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T11:16:56.647",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/052c5ed5a1d96a6b24fd50ccda16fc6841ee7ca3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/74938f83a8abbee8f502dfb5d94213b2497d1edf",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: rkvdec: hevc: guard INTER_REF_PIC_SET_PRED index underflow\n\nst_ref_pic_set_prediction() computes the reference RPS index as\nst_rps_idx - (delta_idx_minus1 + 1) per HEVC spec equation 7-59.\nBoth operands are u8, so when delta_idx_minus1 + 1 exceeds the\ncurrent index the subtraction wraps and the subsequent array access\nat calculated_rps_st_sets[ref_rps_idx] reads far out of bounds.\n\nA userspace V4L2 client that can open the RKVDEC m2m decoder can\nsubmit an EXT_SPS_ST_RPS control with INTER_REF_PIC_SET_PRED set\nand delta_idx_minus1 crafted to trigger the underflow.\n\nReject the entry early when the reference index would underflow."
    }
  ],
  "lastModified": "2026-09-16T15:18:14.850",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}