CVE-2026-89724 is a vulnerability in Linux Kernel
Published on September 11, 2026
media: vicodec: fix out-of-bounds write in FWHT encoder
In the Linux kernel, the following vulnerability has been resolved:
media: vicodec: fix out-of-bounds write in FWHT encoder
vidioc_s_fmt_vid_out() sizes the encoder CAPTURE buffer from the
compressed descriptor pixfmt_fwht, whose sizeimage_mult is 3:
coded_w * coded_h * 3 + sizeof(struct fwht_cframe_hdr). fwht_encode_frame()
encodes one plane per component, and an incompressible plane takes the
FWHT_FRAME_UNENCODED path in encode_plane(), copying the plane verbatim.
For a 4-component pixel format all four planes are full resolution
(width_div == height_div == 1), so a frame that forces every plane
through the unencoded fallback writes
sizeof(struct fwht_cframe_hdr) + 4 * coded_w * coded_h bytes, overrunning
the plane by coded_w * coded_h, which can result in corruption
of adjacent kernel heap memory.
Bump pixfmt_fwht.sizeimage_mult from 3 to 4, matching the largest
components_num among the supported raw formats, so the capture buffer is
always large enough for the unencoded fallback.
Products Associated with CVE-2026-89724
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 16ecf6dff97ce0194a7126e26159492668d47a7e and below 84cfebf7f4229d748cca8eb9c4e1f1c4099d3ab7 is affected.
- Version 16ecf6dff97ce0194a7126e26159492668d47a7e and below 8c14472431e27f13661d0db9d837156eaced0ecb is affected.
- Version 16ecf6dff97ce0194a7126e26159492668d47a7e and below b95315ffc66b39856396c1043618bb4e4d5785ba is affected.
- Version 16ecf6dff97ce0194a7126e26159492668d47a7e and below cf4500ebf6fb57bf4ab83c3dd349a40257dbe2a9 is affected.
- Version 5.0 is affected.
- Before 5.0 is unaffected.
- Version 6.12.109, <= 6.12.* is unaffected.
- Version 6.18.50, <= 6.18.* is unaffected.
- Version 7.2.4, <= 7.2.* is unaffected.
- Version 7.3-rc1, <= * is unaffected.