From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 094F758497B for ; Fri, 11 Sep 2026 20:04:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789157071; cv=none; b=Xby3ky92a/GkliQAKmSSfmu1bM+VQWqPojywKibobxq5jOP9TdeaWMNKIh4E5b3r5988YKJ8MiMtaUNE1ELQBSGV0B+IYwOanHFYoUtOlN6HCVVjgKBByYGUKjQvUFbK9x5xB0HhpdSKvxyO2B4OQ6OqQ+H5S5sAX71DnOSv7ck= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789157071; c=relaxed/simple; bh=0mSEd9gEHKj4gkdmK7SI8tE7TYukZTXxvB6hfjA8Y4E=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=O3kQEiusVn+9Bi537F/RUtMtLmWtKMwSldDz83dDfz0tERP3dVu6eAdV6fdXxnraCCgnrqIUob7w8KVMn2prtOOT9WCADjCMfG13Pv0B9myz+im5RPBF0iTuiEBtV1L3xVAH76O3kK8ZxgPAKGOzWKUe9v2KDlMUalwBwB/CXUY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=IFk61uBm; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="IFk61uBm" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 0E5C11F00898; Fri, 11 Sep 2026 20:04:22 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789157063; bh=Km1VdzTvhwza/03Q9cGoaDE3zS9y1QsaTqeeIodPlo8=; h=From:To:Cc:Subject:Date:Reply-To; b=IFk61uBmnihzGUC8jTgk7wn0mcaQG3E8eerLlKY67V7t07pJdrvXF5xh8+qX4gVGV T7TcXak7WUUrYwso7XYeJTSeCH+mY1kQ1+26YR96G1P9iVKhdGvOTBEEsKNmoUIcHN oScr6rOcCrz+nuZ8/wsszdpj11tz9Tv71W8q+shs= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89724: media: vicodec: fix out-of-bounds write in FWHT encoder Date: Fri, 11 Sep 2026 21:46:53 +0200 Message-ID: <2026091101-CVE-2026-89724-6786@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3136; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=Afthe6OhnT1RDe+Vez7eV8rZxrz74JfklyVEio1o7oE=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIjvjXzInvfnV/Hpiol0PU8F/r7Vh4tsbJoqz8Nn/D BJf9PFoRywLgyATg6yYIsuXbTxH91ccUvQytD0NM4eVCWQIAxenAEzEkIlhnvl5Wes/+3J+1GoY JM901ZS2XKS+lmGeiU2A6u3n0z3m9B3Kzja0ehbjI/wUAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: media: vicodec: fix out-of-bounds write in FWHT encoder vidioc_s_fmt_vid_out() sizes the encoder CAPTURE buffer from the compressed descriptor pixfmt_fwht, whose sizeimage_mult is 3: coded_w * coded_h * 3 + sizeof(struct fwht_cframe_hdr). fwht_encode_frame() encodes one plane per component, and an incompressible plane takes the FWHT_FRAME_UNENCODED path in encode_plane(), copying the plane verbatim. For a 4-component pixel format all four planes are full resolution (width_div == height_div == 1), so a frame that forces every plane through the unencoded fallback writes sizeof(struct fwht_cframe_hdr) + 4 * coded_w * coded_h bytes, overrunning the plane by coded_w * coded_h, which can result in corruption of adjacent kernel heap memory. Bump pixfmt_fwht.sizeimage_mult from 3 to 4, matching the largest components_num among the supported raw formats, so the capture buffer is always large enough for the unencoded fallback. The Linux kernel CVE team has assigned CVE-2026-89724 to this issue. Affected and fixed versions =========================== Issue introduced in 5.0 with commit 16ecf6dff97ce0194a7126e26159492668d47a7e and fixed in 6.12.109 with commit 84cfebf7f4229d748cca8eb9c4e1f1c4099d3ab7 Issue introduced in 5.0 with commit 16ecf6dff97ce0194a7126e26159492668d47a7e and fixed in 6.18.50 with commit 8c14472431e27f13661d0db9d837156eaced0ecb Issue introduced in 5.0 with commit 16ecf6dff97ce0194a7126e26159492668d47a7e and fixed in 7.2.4 with commit b95315ffc66b39856396c1043618bb4e4d5785ba Issue introduced in 5.0 with commit 16ecf6dff97ce0194a7126e26159492668d47a7e and fixed in 7.3-rc1 with commit cf4500ebf6fb57bf4ab83c3dd349a40257dbe2a9 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89724 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/media/test-drivers/vicodec/vicodec-core.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/84cfebf7f4229d748cca8eb9c4e1f1c4099d3ab7 https://git.kernel.org/stable/c/8c14472431e27f13661d0db9d837156eaced0ecb https://git.kernel.org/stable/c/b95315ffc66b39856396c1043618bb4e4d5785ba https://git.kernel.org/stable/c/cf4500ebf6fb57bf4ab83c3dd349a40257dbe2a9