CVE-2026-89878

Summary

In the Linux kernel, the following vulnerability has been resolved:

media: s2255: check firmware size before reading trailing marker

s2255_probe() reads a 4-byte marker and version from the last 8 bytes of the firmware blob (fw->data[fw_size - 8] and [fw_size - 4]). If the firmware file is shorter than 8 bytes, fw_size - 8 underflows and the access reads out of bounds. Validate the firmware size before indexing.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux14d962602c8bf86e63c9b9272be1f0360d0a448a < 6f6a5b0b0a84c2de0e152f2841e57bc226db924faffected
LinuxLinux14d962602c8bf86e63c9b9272be1f0360d0a448a < 8eca0f85eeb0789be40e637bcf9a21c4265b6c6faffected
LinuxLinux14d962602c8bf86e63c9b9272be1f0360d0a448a < ffc27411ea60b8a09f1fea3d664b65210fdeb454affected
LinuxLinux14d962602c8bf86e63c9b9272be1f0360d0a448a < 5626785b0e4665326e4d96736c106161da09b2f0affected
LinuxLinux14d962602c8bf86e63c9b9272be1f0360d0a448a < 3e03f1209c1c8a45a7bc559f4ecd79d9b33f706daffected
LinuxLinux14d962602c8bf86e63c9b9272be1f0360d0a448a < 342632a4d8ba3fafc1556deee0b7a48dd7860336affected
LinuxLinux14d962602c8bf86e63c9b9272be1f0360d0a448a < 7d221859ba45d7228d0138c9a3e55bd3bb31e14eaffected
LinuxLinux14d962602c8bf86e63c9b9272be1f0360d0a448a < 330f2936ab768c7215322a476f033143e8891d28affected
LinuxLinux2.6.28affected
LinuxLinux0 < 2.6.28unaffected
LinuxLinux5.10.270 <= 5.10.*unaffected
LinuxLinux5.15.221 <= 5.15.*unaffected
LinuxLinux6.1.188 <= 6.1.*unaffected
LinuxLinux6.6.157 <= 6.6.*unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.51 <= 6.18.*unaffected
LinuxLinux7.2.5 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References