CVE-2026-68206 (GCVE-0-2026-68206)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: v4l2-ctrls: validate HEVC active reference counts
HEVC slice parameters are shared stateless V4L2 controls, but the common
validation path does not verify the active L0/L1 reference counts before
driver-specific code consumes them.
The original report came from Cedrus, but the active count bounds are
not Cedrus-specific. Validate them in the common HEVC slice control path
so stateless HEVC drivers get the same basic guarantees as soon as the
control is queued.
Do not reject ref_idx_l0/ref_idx_l1 entries here. Existing userspace may
use out-of-range sentinel values such as 0xff for missing references, and
some hardware can use that information for concealment. Keep this common
check limited to the active reference counts.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d395a78db9eabd12633b39e05c80e803543b6590 Version: d395a78db9eabd12633b39e05c80e803543b6590 Version: d395a78db9eabd12633b39e05c80e803543b6590 Version: d395a78db9eabd12633b39e05c80e803543b6590 Version: d395a78db9eabd12633b39e05c80e803543b6590 Version: d395a78db9eabd12633b39e05c80e803543b6590 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/v4l2-core/v4l2-ctrls-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3299c3905f3fb439ebd892658b87bc76c93ae116",
"status": "affected",
"version": "d395a78db9eabd12633b39e05c80e803543b6590",
"versionType": "git"
},
{
"lessThan": "9a998cc1c348769262d433acb7d238c5fac4b2e0",
"status": "affected",
"version": "d395a78db9eabd12633b39e05c80e803543b6590",
"versionType": "git"
},
{
"lessThan": "dbaf0e0023e2f9332c5164822def7f80b7d2c5ef",
"status": "affected",
"version": "d395a78db9eabd12633b39e05c80e803543b6590",
"versionType": "git"
},
{
"lessThan": "3068ab802fc98b121dcb451e1f7f4d338ffc7a19",
"status": "affected",
"version": "d395a78db9eabd12633b39e05c80e803543b6590",
"versionType": "git"
},
{
"lessThan": "b01df98a6669d2b67d8aed816021b327fd905998",
"status": "affected",
"version": "d395a78db9eabd12633b39e05c80e803543b6590",
"versionType": "git"
},
{
"lessThan": "afbe4bc252d90a6f8fad869b06d5430f615f22f9",
"status": "affected",
"version": "d395a78db9eabd12633b39e05c80e803543b6590",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/v4l2-core/v4l2-ctrls-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: v4l2-ctrls: validate HEVC active reference counts\n\nHEVC slice parameters are shared stateless V4L2 controls, but the common\nvalidation path does not verify the active L0/L1 reference counts before\ndriver-specific code consumes them.\n\nThe original report came from Cedrus, but the active count bounds are\nnot Cedrus-specific. Validate them in the common HEVC slice control path\nso stateless HEVC drivers get the same basic guarantees as soon as the\ncontrol is queued.\n\nDo not reject ref_idx_l0/ref_idx_l1 entries here. Existing userspace may\nuse out-of-range sentinel values such as 0xff for missing references, and\nsome hardware can use that information for concealment. Keep this common\ncheck limited to the active reference counts."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The control is only settable through VIDIOC_S_EXT_CTRLS on the local V4L2 stateless decoder node (/dev/videoN), followed by QBUF/STREAMON on the same fd. There is no network or remote path into the HEVC slice-params control.\nAC:L - The attacker supplies num_ref_idx_l0/l1_active_minus1 verbatim as a u8; any value in 16..254 deterministically drives the loops in cedrus_h265_is_low_delay() and rkvdec_hevc set_ps_field() out of bounds on the very next decode run. No race, timing window, or uncontrollable memory layout is involved.\nPR:L - Only an unprivileged local account holding the video device node is required (typically the \u0027video\u0027 group, or the media/codec service reachable from sandboxed apps on Android and embedded Allwinner/Rockchip devices). cedrus_try_ctrl() checks only SPS chroma format and bit depth; no capability or root check exists on the path.\nUI:N - The attacking process performs the whole sequence itself: open the decoder, set the crafted HEVC slice-params control, queue buffers and start streaming. No victim action, media file, or mount is needed.\nS:U - The out-of-bounds accesses stay inside the kernel\u0027s own slab and DMA memory within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - decode_params-\u003edpb[] holds 16 16-byte entries at the tail of a ~336-byte control allocation, so an index up to 255 reads roughly 3.8 KB of adjacent kernel heap; the pred-weight loops likewise read 240 bytes past slice_params. Those OOB bytes are fed into decoder SRAM and steer the low-delay decision, giving an attacker-steerable oracle over unrelated kernel memory.\nI:H - In rkvdec-hevc, REF_PIC_IDX_L0(i)/REF_PIC_LONG_TERM_L1(i) with i up to 255 resolve to bit offset ~1276 in an 8-word rkvdec_rps_packet, so set_ps_field() performs an out-of-bounds write of attacker-chosen bits at an attacker-chosen offset into (and past the end of) the coherent DMA priv_tbl, corrupting hardware descriptor state and adjacent memory.\nA:H - Reading several kilobytes past a slab object can walk into an unmapped or poisoned region and trips KASAN/hardening checks, while the rkvdec out-of-bounds write corrupts the DMA table handed to the decoder; either yields a kernel oops or wedged hardware, repeatable at will from an unprivileged process."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:26.837Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3299c3905f3fb439ebd892658b87bc76c93ae116"
},
{
"url": "https://git.kernel.org/stable/c/9a998cc1c348769262d433acb7d238c5fac4b2e0"
},
{
"url": "https://git.kernel.org/stable/c/dbaf0e0023e2f9332c5164822def7f80b7d2c5ef"
},
{
"url": "https://git.kernel.org/stable/c/3068ab802fc98b121dcb451e1f7f4d338ffc7a19"
},
{
"url": "https://git.kernel.org/stable/c/b01df98a6669d2b67d8aed816021b327fd905998"
},
{
"url": "https://git.kernel.org/stable/c/afbe4bc252d90a6f8fad869b06d5430f615f22f9"
}
],
"title": "media: v4l2-ctrls: validate HEVC active reference counts",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68206",
"datePublished": "2026-08-10T12:00:25.309Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:26.837Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…