HarborGuard / CVE
Back to search
HIGHCVE-2026-43256Published Modified CNA Linux

CVE-2026-43256: media: qcom: camss: vfe: Fix out-of-bounds access in vfe_isr_reg_update()

In the Linux kernel, the following vulnerability has been resolved: media: qcom: camss: vfe: Fix out-of-bounds access in vfe_isr_reg_update() vfe_isr() iterates using MSM_VFE_IMAGE_MASTERS_NUM(7) as the loop bound and passes the index to vfe_isr_reg_update(). However, vfe->line[] array is defined with VFE_LINE_NUM_MAX(4): struct vfe_line line[VFE_LINE_NUM_MAX]; When index is 4, 5, 6, the access to vfe->line[line_id] exceeds the array bounds and resulting in out-of-bounds memory access. Fix this by using separate loops for output lines and write masters.

Metrics

CVSS v3.1
7.8
Severity
HIGH
Fixed in
0
Affected Products
2

Fix available

00c074e80921fd18984b75836730d76c768c84f651b103307df6d461a0731be25aca69ad0335b09336.1.1676.6.1286.12.756.18.166.19.67.0d965919af524e68cb2ab1a685872050ad2ee933de6cbf765686fb6c1d8f2530b3daf6c66efc92f5de7a38ecda2498e7ce998793ac2a46ca47317635dfade67c88870f497a13ed450ba01f7236c92dd9b
Affected packages
  • Linux / Linux
    < e6cbf765686fb6c1d8f2530b3daf6c66efc92f5d (from 4edc8eae715cecf5f8bf12a0c77c281f336c37db) · < 0c074e80921fd18984b75836730d76c768c84f65 (from 4edc8eae715cecf5f8bf12a0c77c281f336c37db) · < 1b103307df6d461a0731be25aca69ad0335b0933 (from 4edc8eae715cecf5f8bf12a0c77c281f336c37db) · < fade67c88870f497a13ed450ba01f7236c92dd9b (from 4edc8eae715cecf5f8bf12a0c77c281f336c37db) · < e7a38ecda2498e7ce998793ac2a46ca47317635d (from 4edc8eae715cecf5f8bf12a0c77c281f336c37db) · < d965919af524e68cb2ab1a685872050ad2ee933d (from 4edc8eae715cecf5f8bf12a0c77c281f336c37db)
  • Linux / Linux
    5.18
    Fixed in 0, 6.1.167, 6.6.128, 6.12.75, 6.18.16, 6.19.6, 7.0
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H