CVE-2026-43235: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: media: iris: Add missing platform data entries for SM8750 Two platform-data fields for SM8750 were missed: - get_vpu_buffer_size = iris_vpu33_buf_size Without this, the driver fails to allocate the required internal buffers, leading to basic decode/encode failures during session bring-up. - max_core_mbps = ((7680 * 4320) / 256) * 60 Without this capability exposed, capability checks are incomplete and v4l2-compliance for encoder fails.

Affected products

  • Linux Linux Kernel: from 6.18, before 6.18.17 (fixed in 6.18.17); from 6.19, before 6.19.6 (fixed in 6.19.6)

Published 2026-05-06. Last modified 2026-06-17.