{"id":"CVE-2026-89873","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: v4l2-ctrls: validate HEVC EXT SPS RPS counts\n\nThe HEVC SPS control carries the short-term and long-term RPS counts\nthat decoder drivers use to walk the matching …","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: v4l2-ctrls: validate HEVC EXT SPS RPS counts\n\nThe HEVC SPS control carries the short-term and long-term RPS counts\nthat decoder drivers use to walk the matching …","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"Linux","product":"Linux","affected":["Linux >= c9a59dc2acc72789d5c778af080d1e65af84862c < 30f85a7c59113a8844b276efc010085a34f912e9","Linux >= c9a59dc2acc72789d5c778af080d1e65af84862c < 796b5c6d4f1615d59d5d8fe5a38fae6bfdfe878e","Linux 7.0"],"published":"2026-09-16","updated":"2026-09-16","sourceUpdated":"2026-09-16T15:18:14.330","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-89873","references":[{"url":"https://git.kernel.org/stable/c/30f85a7c59113a8844b276efc010085a34f912e9","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/796b5c6d4f1615d59d5d8fe5a38fae6bfdfe878e","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-16T10:53:53.987Z","epss":0.00154,"epssPercentile":0.04932,"slug":"CVE-2026-89873","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmedia: v4l2-ctrls: validate HEVC EXT SPS RPS counts\n\nThe HEVC SPS control carries the short-term and long-term RPS counts\nthat decoder drivers use to walk the matching EXT SPS dynamic arrays.\nReject SPS values that exceed the HEVC limits of 64 short-term sets and\n32 long-term references so drivers cannot later index beyond those\ncontrols.\n\nAlso reject EXT SPS ST RPS entries whose negative or positive picture\ncounts exceed the 16-entry arrays, or whose combined delta-POC count\nexceeds the HEVC DPB maximum.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":205184,"id":"CVE-2026-89873","ts":1789570705629,"field":"cvss","old":null,"new":"7.8"},{"seq":205183,"id":"CVE-2026-89873","ts":1789570705629,"field":"severity","old":"none","new":"high"}]}