media: s2255: check firmware size before reading trailing marker
Summary
| CVE | CVE-2026-89878 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-16 11:16:56 UTC |
| Updated | 2026-09-16 11:16:56 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
media: s2255: check firmware size before reading trailing marker
s2255_probe() reads a 4-byte marker and version from the last 8 bytes
of the firmware blob (fw->data[fw_size - 8] and [fw_size - 4]). If the
firmware file is shorter than 8 bytes, fw_size - 8 underflows and the
access reads out of bounds. Validate the firmware size before indexing. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 14d962602c8bf86e63c9b9272be1f0360d0a448a 6f6a5b0b0a84c2de0e152f2841e57bc226db924f git |
Not specified |
| CNA |
Linux |
Linux |
affected 14d962602c8bf86e63c9b9272be1f0360d0a448a 8eca0f85eeb0789be40e637bcf9a21c4265b6c6f git |
Not specified |
| CNA |
Linux |
Linux |
affected 14d962602c8bf86e63c9b9272be1f0360d0a448a ffc27411ea60b8a09f1fea3d664b65210fdeb454 git |
Not specified |
| CNA |
Linux |
Linux |
affected 14d962602c8bf86e63c9b9272be1f0360d0a448a 5626785b0e4665326e4d96736c106161da09b2f0 git |
Not specified |
| CNA |
Linux |
Linux |
affected 14d962602c8bf86e63c9b9272be1f0360d0a448a 3e03f1209c1c8a45a7bc559f4ecd79d9b33f706d git |
Not specified |
| CNA |
Linux |
Linux |
affected 14d962602c8bf86e63c9b9272be1f0360d0a448a 342632a4d8ba3fafc1556deee0b7a48dd7860336 git |
Not specified |
| CNA |
Linux |
Linux |
affected 14d962602c8bf86e63c9b9272be1f0360d0a448a 7d221859ba45d7228d0138c9a3e55bd3bb31e14e git |
Not specified |
| CNA |
Linux |
Linux |
affected 14d962602c8bf86e63c9b9272be1f0360d0a448a 330f2936ab768c7215322a476f033143e8891d28 git |
Not specified |
| CNA |
Linux |
Linux |
affected 2.6.28 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 2.6.28 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.10.270 5.10.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.15.221 5.15.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.1.188 6.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.157 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.110 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.51 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.5 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/330f2936ab768c7215322a476f033143e8891d28 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/3e03f1209c1c8a45a7bc559f4ecd79d9b33f706d |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/7d221859ba45d7228d0138c9a3e55bd3bb31e14e |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/6f6a5b0b0a84c2de0e152f2841e57bc226db924f |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/342632a4d8ba3fafc1556deee0b7a48dd7860336 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/8eca0f85eeb0789be40e637bcf9a21c4265b6c6f |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/ffc27411ea60b8a09f1fea3d664b65210fdeb454 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/5626785b0e4665326e4d96736c106161da09b2f0 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.