# CVE-2026-89724

## Summary

- **CVE ID:** CVE-2026-89724
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 14, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

media: vicodec: fix out-of-bounds write in FWHT encoder

vidioc_s_fmt_vid_out() sizes the encoder CAPTURE buffer from the
compressed descriptor pixfmt_fwht, whose sizeimage_mult is 3:
coded_w * coded_h * 3 + sizeof(struct fwht_cframe_hdr). fwht_encode_frame()
encodes one plane per component, and an incompressible plane takes the
FWHT_FRAME_UNENCODED path in encode_plane(), copying the plane verbatim.

For a 4-component pixel format all four planes are full resolution
(width_div == height_div == 1), so a frame that forces every plane
through the unencoded fallback writes
sizeof(struct fwht_cframe_hdr) + 4 * coded_w * coded_h bytes, overrunning
the plane by coded_w * coded_h, which can result in corruption
of adjacent kernel heap memory.

Bump pixfmt_fwht.sizeimage_mult from 3 to 4, matching the largest
components_num among the supported raw formats, so the capture buffer is
always large enough for the unencoded fallback.

## Affected Products

- Linux — Linux (16ecf6dff97ce0194a7126e26159492668d47a7e)
- Linux — Linux (5.0)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (5.10.270)
- Linux — Linux (5.15.221)
- Linux — Linux (6.1.188)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/84cfebf7f4229d748cca8eb9c4e1f1c4099d3ab7)
- [CNA](https://git.kernel.org/stable/c/8c14472431e27f13661d0db9d837156eaced0ecb)
- [CNA](https://git.kernel.org/stable/c/b95315ffc66b39856396c1043618bb4e4d5785ba)
- [CNA](https://git.kernel.org/stable/c/cf4500ebf6fb57bf4ab83c3dd349a40257dbe2a9)
- [CNA](https://git.kernel.org/stable/c/f7ae26c100a6c26c2a166d2c41e73188067b36bd)
- [CNA](https://git.kernel.org/stable/c/6ea647e76c44387d5c1c635df4604c2154d9060e)
- [CNA](https://git.kernel.org/stable/c/d40838a63f2bd6a3df0a6cdd8ff1d5c6366e8fff)
- [CNA](https://git.kernel.org/stable/c/e21cccc29b840930cd9dcfdf1139658063a681af)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.16%
- **EPSS Percentile:** 6.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._