Vulnerability Details CVE-2026-56920
In s_decode_vui_param of fw_hevc_dec_header.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 21.2%
CVSS Severity
CVSS v3 Score 8.8