{"id":"CVE-2026-89724","title":"kernel: media: vicodec: fix out-of-bounds write in FWHT encoder (CVE-2026-89724)","summary":"A flaw was found in the Linux kernel's `media: vicodec` component. An out-of-bounds write vulnerability exists in the FWHT encoder due to incorrect buffer sizing during video output format handling. This issue allows an attacker to cause c…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-787","vendor":"Red Hat","product":"Linux","affected":["Linux >= 16ecf6dff97ce0194a7126e26159492668d47a7e < f7ae26c100a6c26c2a166d2c41e73188067b36bd","Linux >= 16ecf6dff97ce0194a7126e26159492668d47a7e < 6ea647e76c44387d5c1c635df4604c2154d9060e","Linux >= 16ecf6dff97ce0194a7126e26159492668d47a7e < d40838a63f2bd6a3df0a6cdd8ff1d5c6366e8fff","Linux >= 16ecf6dff97ce0194a7126e26159492668d47a7e < e21cccc29b840930cd9dcfdf1139658063a681af","Linux >= 16ecf6dff97ce0194a7126e26159492668d47a7e < 84cfebf7f4229d748cca8eb9c4e1f1c4099d3ab7","Linux >= 16ecf6dff97ce0194a7126e26159492668d47a7e < 8c14472431e27f13661d0db9d837156eaced0ecb","Linux >= 16ecf6dff97ce0194a7126e26159492668d47a7e < b95315ffc66b39856396c1043618bb4e4d5785ba","Linux >= 16ecf6dff97ce0194a7126e26159492668d47a7e < cf4500ebf6fb57bf4ab83c3dd349a40257dbe2a9","Linux 5.0"],"published":"2026-09-11","updated":"2026-09-15","sourceUpdated":"2026-09-15T11:02:37+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89724.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89724.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89724"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532428"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89724"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89724"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89724.mbox"},{"url":"https://git.kernel.org/stable/c/f7ae26c100a6c26c2a166d2c41e73188067b36bd"},{"url":"https://git.kernel.org/stable/c/6ea647e76c44387d5c1c635df4604c2154d9060e"},{"url":"https://git.kernel.org/stable/c/d40838a63f2bd6a3df0a6cdd8ff1d5c6366e8fff"},{"url":"https://git.kernel.org/stable/c/e21cccc29b840930cd9dcfdf1139658063a681af"},{"url":"https://git.kernel.org/stable/c/84cfebf7f4229d748cca8eb9c4e1f1c4099d3ab7"},{"url":"https://git.kernel.org/stable/c/8c14472431e27f13661d0db9d837156eaced0ecb"},{"url":"https://git.kernel.org/stable/c/b95315ffc66b39856396c1043618bb4e4d5785ba"},{"url":"https://git.kernel.org/stable/c/cf4500ebf6fb57bf4ab83c3dd349a40257dbe2a9"}],"tags":["csaf","vex","red-hat","cve.org","score-dispute"],"epss":0.00176,"epssPercentile":0.0632,"scores":{"vendor":5.5,"cna":7.8},"ingestedAt":"2026-09-14T15:23:07.449Z","slug":"CVE-2026-89724","body":"## Overview\n\nA flaw was found in the Linux kernel's `media: vicodec` component. An out-of-bounds write vulnerability exists in the FWHT encoder due to incorrect buffer sizing during video output format handling. This issue allows an attacker to cause corruption of adjacent kernel heap memory, which could lead to system instability or a denial of service.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89724.json)\n\n**kernel: media: vicodec: fix out-of-bounds write in FWHT encoder** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-15.\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nRefer to the advisory for fix availability.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":203904,"id":"CVE-2026-89724","ts":1789490220130,"field":"cvss","old":"7.8","new":"5.5"},{"seq":203903,"id":"CVE-2026-89724","ts":1789490220130,"field":"severity","old":"high","new":"medium"},{"seq":197693,"id":"CVE-2026-89724","ts":1789384318433,"field":"cvss","old":"6.3","new":"7.8"},{"seq":197692,"id":"CVE-2026-89724","ts":1789384318433,"field":"severity","old":"medium","new":"high"},{"seq":183849,"id":"CVE-2026-89724","ts":1789356677662,"field":"cvss","old":"7.8","new":"6.3"},{"seq":183848,"id":"CVE-2026-89724","ts":1789356677662,"field":"severity","old":"high","new":"medium"},{"seq":153610,"id":"CVE-2026-89724","ts":1789285351493,"field":"cvss","old":null,"new":"7.8"},{"seq":153609,"id":"CVE-2026-89724","ts":1789285351493,"field":"severity","old":"none","new":"high"},{"seq":147219,"id":"CVE-2026-89724","ts":1789270202132,"field":"cvss","old":null,"new":"6.3"},{"seq":147218,"id":"CVE-2026-89724","ts":1789270202132,"field":"severity","old":"none","new":"medium"},{"seq":108964,"id":"CVE-2026-89724","ts":1789183729758,"field":"cvss","old":null,"new":"6.3"},{"seq":108963,"id":"CVE-2026-89724","ts":1789183729758,"field":"severity","old":"none","new":"medium"}]}