CVE-2026-97579

HIGHCVSS 7.8/10

Last modified

CVE-2026-97579 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: bound AV1 tile-start copy to the array capacity vdec_av1_slice_setup_tile() copies tile_cols + 1 / tile_rows + 1 entries into mi_col_starts[] / mi_row_starts[] from the bitstream tile_info. Bound the copy to the array capacity..

Description

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: bound AV1 tile-start copy to the array capacity vdec_av1_slice_setup_tile() copies tile_cols + 1 / tile_rows + 1 entries into mi_col_starts[] / mi_row_starts[] from the bitstream tile_info. Bound the copy to the array capacity.

Metrics

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 0934d37596151edce115c6d0843a9ad7d5e5d232, < ad47a250afafa3a51cfb4a004463ff28e66c596e; >= 0934d37596151edce115c6d0843a9ad7d5e5d232, < 7992059c045780095ba5a696dcb2f5400a82803c; >= 0934d37596151edce115c6d0843a9ad7d5e5d232, < eb0ea3898e3921900939e30c3946dd2b52281859; >= 0934d37596151edce115c6d0843a9ad7d5e5d232, < 37bef2170d4c88fc3d708eecf3ef0f4032bc1372
LinuxLinux6.6

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-97579?
In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: bound AV1 tile-start copy to the array capacity vdec_av1_slice_setup_tile() copies tile_cols + 1 / tile_rows + 1 entries into mi_col_starts[] / mi_row_starts[] from the bitstream tile_info. Bound the copy to the array capacity.
How severe is CVE-2026-97579?
CVE-2026-97579 has a CVSS score of 7.8/10 (HIGH severity).
How do I fix CVE-2026-97579?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-97579?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST