CVE-2026-43256
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/05/2026
Last modified:
08/05/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
media: qcom: camss: vfe: Fix out-of-bounds access in vfe_isr_reg_update()<br />
<br />
vfe_isr() iterates using MSM_VFE_IMAGE_MASTERS_NUM(7) as the loop<br />
bound and passes the index to vfe_isr_reg_update(). However,<br />
vfe->line[] array is defined with VFE_LINE_NUM_MAX(4):<br />
<br />
struct vfe_line line[VFE_LINE_NUM_MAX];<br />
<br />
When index is 4, 5, 6, the access to vfe->line[line_id] exceeds<br />
the array bounds and resulting in out-of-bounds memory access.<br />
<br />
Fix this by using separate loops for output lines and write masters.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/0c074e80921fd18984b75836730d76c768c84f65
- https://git.kernel.org/stable/c/1b103307df6d461a0731be25aca69ad0335b0933
- https://git.kernel.org/stable/c/d965919af524e68cb2ab1a685872050ad2ee933d
- https://git.kernel.org/stable/c/e6cbf765686fb6c1d8f2530b3daf6c66efc92f5d
- https://git.kernel.org/stable/c/e7a38ecda2498e7ce998793ac2a46ca47317635d
- https://git.kernel.org/stable/c/fade67c88870f497a13ed450ba01f7236c92dd9b



