CVE-2026-68230: media: amlogic-c3: Add validations for ae and awb config

Published Aug 10, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

media: amlogic-c3: Add validations for ae and awb config

Avoid invalid memory access if the zonesnum is bigger than zoneweight.

This patch fixes the following smatch errors: drivers/media/platform/amlogic/c3/isp/c3-isp-params.c:111 c3ispparamsawbwt() error: buffer overflow 'cfg->zoneweight' 768 <= u32max drivers/media/platform/amlogic/c3/isp/c3-isp-params.c:111 c3ispparamsawbwt() error: buffer overflow 'cfg->zoneweight' 768 <= u32max drivers/media/platform/amlogic/c3/isp/c3-isp-params.c:227 c3ispparamsaewt() error: buffer overflow 'cfg->zoneweight' 255 <= u32max drivers/media/platform/amlogic/c3/isp/c3-isp-params.c:227 c3ispparamsaewt() error: buffer overflow 'cfg->zoneweight' 255 <= u32max

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Apply the kernel fix that adds validations for ae and awb config zone_weight to avoid buffer overflow when zones_num is bigger than the supported limit (as addressed in c3_isp_params_awb_wt() and c3_isp_params_ae_wt()).

    Linux kernel (media: amlogic-c3) Validate ae and awb zone_weight when zones_num is bigger than allowed = Add validations for ae and awb config zone_weight (prevent buffer overflow)

Event History

Aug 10, 2026
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
Description
Data Sourced
via NVD·01:20 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-68230?

The severity of CVE-2026-68230 is classified as 27.

2

What type of vulnerability is CVE-2026-68230?

CVE-2026-68230 is classified as a Buffer Overflow vulnerability.

3

How do I fix CVE-2026-68230?

To fix CVE-2026-68230, update the Linux kernel with the patch that adds validations for ae and awb configuration.

4

What is affected by CVE-2026-68230?

CVE-2026-68230 affects the media subsystem in the Amlogic C3 kernel drivers.

5

When was CVE-2026-68230 published?

CVE-2026-68230 was published on August 10, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203