CVE-2026-93236: vulnerability in Linux
media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common
Published
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.2%
exploitation probability
0.2%top 90% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common
When VIDIOC_TRY_FMT is called with an unsupported pixel format on the
OUTPUT queue, vdec_try_fmt_common() falls back to V4L2_PIX_FMT_MPEG2.
However, if a distro has locally patched MPEG2 support out (as it has
been broken for some time) the platform format table does not contain
MPEG2 so find_format() returns NULL and the subsequent dereference of
fmt_out->max_width triggers a NULL pointer dereference.
Fix this by falling back to the first format in the platform's format
array instead of hardcoding V4L2_PIX_FMT_MPEG2. This is always valid
since every platform defines at least one format.
Affected products
Linux · LinuxRelated CVEs — Linux
In the same product, most dangerous first.
CVE-2024-53197HIGHALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devicesEPSS 4.1%KEVCVE-2026-31431HIGHcrypto: algif_aead - Revert to operating out-of-placeEPSS 3.4%KEVCVE-2024-53104HIGHmedia: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_formatEPSS 3.4%KEVCVE-2025-39682CRITICALtls: fix handling of zero-length records on the rx_listEPSS 2.9%KEVCVE-2024-36971HIGHnet: fix __dst_negative_advice() raceEPSS 2.7%KEVCVE-2024-53150HIGHALSA: usb-audio: Fix out of bounds reads when finding clock sourcesEPSS 1.4%KEV
References
https://git.kernel.org/stable/c/20aa934ace6917262ff579a73ec018d06a7bad1chttps://git.kernel.org/stable/c/276f28672bb6d5d5feca78db4219c7b5adf1be26https://git.kernel.org/stable/c/3839b6be2279fc4f558723f2c0fbfc9c42070958https://git.kernel.org/stable/c/680a89683197cdfe4e03e6fd7755454c647d39c1https://git.kernel.org/stable/c/96dafbae77f50bfe2228bcfedcd8652c5e5f08e8https://git.kernel.org/stable/c/c620906fb1b2ad75d408ea9d06040d66952d4a31https://git.kernel.org/stable/c/d61ba609c3226af3c84268ba606ea06ee63e511bhttps://git.kernel.org/stable/c/f2375a308640e401c142c5426d52c3d10e016d25