Executive brief
A vulnerability was identified in the Linux kernel's Rockchip camera interface driver (rkcif). This flaw could allow the system to access memory outside of its intended boundaries when processing camera data. In practice, this could lead to system instability or crashes on devices using Rockchip hardware, such as certain embedded systems or media players.
Technical details
An off-by-one vulnerability exists in the Rockchip Camera Interface (rkcif) driver within the Linux kernel, specifically in the rkcif-capture-mipi.c component. The functions rkcif_mipi_get_reg and rkcif_mipi_id_get_reg used incorrect comparison operators ('>' instead of '>=') when validating array indices against maximum bounds. This flaw allows an out-of-bounds read of one element beyond the end of the 'blocks', 'regs', and 'regs_id' arrays. The issue has been resolved by updating the boundary checks to use ARRAY_SIZE() and the correct comparison operators. The vulnerability was introduced in the support for rk3568 vicap mipi capture.
Affected products
- Linux Linux Kernel rkcif driver support for rk3568 vicap mipi capture
Timeline
- 2026-02-20: other: Patch authored
- 2026-06-09: disclosed: CVE published