CVE-2026-43310

MEDIUM

media: verisilicon: Avoid G2 bus error while decoding H.264 and HEVC

Title source: cna
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: media: verisilicon: Avoid G2 bus error while decoding H.264 and HEVC For the i.MX8MQ platform, there is a hardware limitation: the g1 VPU and g2 VPU cannot decode simultaneously; otherwise, it will cause below bus error and produce corrupted pictures, even potentially lead to system hang. [ 110.527986] hantro-vpu 38310000.video-codec: frame decode timed out. [ 110.583517] hantro-vpu 38310000.video-codec: bus error detected. Therefore, it is necessary to ensure that g1 and g2 operate alternately. This allows for successful multi-instance decoding of H.264 and HEVC. To achieve this, g1 and g2 share the same v4l2_m2m_dev, and then the v4l2_m2m_dev can handle the scheduling.

Scores

CVSS v3 5.5
EPSS 0.0001
EPSS Percentile 3.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (7)
Linux/Linux < 5.14
Linux/Linux 5.14
Linux/Linux 6.19.6 - 6.19.*
Linux/Linux 7.0
Linux/Linux cb5dd5a0fa518dff14ff2b90837c3c8f98f4dd5c - 286d629d10640bc22f3bf46aa4f356eb7975e862
Linux/Linux cb5dd5a0fa518dff14ff2b90837c3c8f98f4dd5c - e0203ddf9af7c8e170e1e99ce83b4dc07f0cd765
linux/linux_kernel 5.14 - 6.19.6
Published May 08, 2026
Tracked Since May 08, 2026