« Volver al listado

CVE-2026-97578

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

media: verisilicon: rockchip: guard VPU981 AV1 divisor and tile buffer

rockchip_vpu981_av1_dec_set_tile_info() divides context_update_tile_id by tile_info->tile_cols and writes one descriptor per tile into the tile_info DMA buffer, which holds AV1_MAX_TILES entries; tile_cols and tile_rows come from the bitstream. Guard the division against a zero tile_cols by initialising the context-update values to zero and computing them only when tile_cols is non-zero, and stop the descriptor writes once the tile_info buffer is full. The tile geometry written to the hardware registers is left unmodified; the per-dimension and total tile bounds are enforced by the control validation.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local en kernel Linux (AV:L, PR:L) que permite corrupción de memoria y DoS mediante división por cero en controlador de decodificador de video, requiere escalada de privilegios desde cuenta local.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97578",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "727a400686a2c0d25015c9e44916a59b72882f83",
              "lessThan": "8659e5fc21a82e00fb2db1557f2e06f0fca06b90",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "727a400686a2c0d25015c9e44916a59b72882f83",
              "lessThan": "7baa7bb1b784c19170df8c99466fa412040eb431",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "727a400686a2c0d25015c9e44916a59b72882f83",
              "lessThan": "8f19d869a9f6800547c9ad7ebaf3b94f973dab50",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "727a400686a2c0d25015c9e44916a59b72882f83",
              "lessThan": "6b7a281a815ae7c5e7bb2aad039ffea9bc933157",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "727a400686a2c0d25015c9e44916a59b72882f83",
              "lessThan": "b84f6533a8ed2fd7b282fc7ab4b8efadc745a89c",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/media/platform/verisilicon/rockchip_vpu981_hw_av1_dec.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.5"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.5",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/media/platform/verisilicon/rockchip_vpu981_hw_av1_dec.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:08.567",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/6b7a281a815ae7c5e7bb2aad039ffea9bc933157",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7baa7bb1b784c19170df8c99466fa412040eb431",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8659e5fc21a82e00fb2db1557f2e06f0fca06b90",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8f19d869a9f6800547c9ad7ebaf3b94f973dab50",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b84f6533a8ed2fd7b282fc7ab4b8efadc745a89c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: verisilicon: rockchip: guard VPU981 AV1 divisor and tile buffer\n\nrockchip_vpu981_av1_dec_set_tile_info() divides context_update_tile_id by\ntile_info->tile_cols and writes one descriptor per tile into the tile_info\nDMA buffer, which holds AV1_MAX_TILES entries; tile_cols and tile_rows\ncome from the bitstream. Guard the division against a zero tile_cols by\ninitialising the context-update values to zero and computing them only\nwhen tile_cols is non-zero, and stop the descriptor writes once the\ntile_info buffer is full. The tile geometry written to the hardware\nregisters is left unmodified; the per-dimension and total tile bounds are\nenforced by the control validation."
    }
  ],
  "lastModified": "2026-10-03T11:18:05.197",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}