← לוח פגיעויות

CVE-2026-56920

גבוהה 8.8

תיאור (מקור, אנגלית)

In s_decode_vui_param of fw_hevc_dec_header.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

מדדים

CVSS 3.1
8.8 (HIGH) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-27/9/2026
CWE
CWE-787

מוצרים מושפעים

google: android

קישורים