{"id":"CVE-2026-93236","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common\n\nWhen VIDIOC_TRY_FMT is called with an unsupported pixel format on the\nOUTPUT queue, vdec_try_fmt_comm…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common\n\nWhen VIDIOC_TRY_FMT is called with an unsupported pixel format on the\nOUTPUT queue, vdec_try_fmt_comm…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 3e7f51bd96077acad6acd7b45668f65b44233c4e < 276f28672bb6d5d5feca78db4219c7b5adf1be26","Linux >= 3e7f51bd96077acad6acd7b45668f65b44233c4e < c620906fb1b2ad75d408ea9d06040d66952d4a31","Linux >= 3e7f51bd96077acad6acd7b45668f65b44233c4e < 3839b6be2279fc4f558723f2c0fbfc9c42070958","Linux >= 3e7f51bd96077acad6acd7b45668f65b44233c4e < 680a89683197cdfe4e03e6fd7755454c647d39c1","Linux >= 3e7f51bd96077acad6acd7b45668f65b44233c4e < f2375a308640e401c142c5426d52c3d10e016d25","Linux >= 3e7f51bd96077acad6acd7b45668f65b44233c4e < 96dafbae77f50bfe2228bcfedcd8652c5e5f08e8","Linux >= 3e7f51bd96077acad6acd7b45668f65b44233c4e < d61ba609c3226af3c84268ba606ea06ee63e511b","Linux >= 3e7f51bd96077acad6acd7b45668f65b44233c4e < 20aa934ace6917262ff579a73ec018d06a7bad1c","Linux 5.3"],"published":"2026-09-24","updated":"2026-09-24","sourceUpdated":"2026-09-24T16:17:19.297","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93236","references":[{"url":"https://git.kernel.org/stable/c/20aa934ace6917262ff579a73ec018d06a7bad1c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/276f28672bb6d5d5feca78db4219c7b5adf1be26","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3839b6be2279fc4f558723f2c0fbfc9c42070958","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/680a89683197cdfe4e03e6fd7755454c647d39c1","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/96dafbae77f50bfe2228bcfedcd8652c5e5f08e8","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c620906fb1b2ad75d408ea9d06040d66952d4a31","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d61ba609c3226af3c84268ba606ea06ee63e511b","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f2375a308640e401c142c5426d52c3d10e016d25","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-24T15:45:56.659Z","slug":"CVE-2026-93236","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmedia: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common\n\nWhen VIDIOC_TRY_FMT is called with an unsupported pixel format on the\nOUTPUT queue, vdec_try_fmt_common() falls back to V4L2_PIX_FMT_MPEG2.\nHowever, if a distro has locally patched MPEG2 support out (as it has\nbeen broken for some time) the platform format table does not contain\nMPEG2 so find_format() returns NULL and the subsequent dereference of\nfmt_out->max_width triggers a NULL pointer dereference.\n\nFix this by falling back to the first format in the platform's format\narray instead of hardcoding V4L2_PIX_FMT_MPEG2. This is always valid\nsince every platform defines at least one format.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}