CVE-2026-89878: vulnerability in Linux
media: s2255: check firmware size before reading trailing marker
Published
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.2%
exploitation probability
0.2%top 90% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
media: s2255: check firmware size before reading trailing marker
s2255_probe() reads a 4-byte marker and version from the last 8 bytes
of the firmware blob (fw->data[fw_size - 8] and [fw_size - 4]). If the
firmware file is shorter than 8 bytes, fw_size - 8 underflows and the
access reads out of bounds. Validate the firmware size before indexing.
Affected products
Linux · LinuxRelated CVEs — Linux
In the same product, most dangerous first.
CVE-2024-53197HIGHALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devicesEPSS 4.1%KEVCVE-2026-31431HIGHcrypto: algif_aead - Revert to operating out-of-placeEPSS 3.4%KEVCVE-2024-53104HIGHmedia: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_formatEPSS 3.4%KEVCVE-2025-39682CRITICALtls: fix handling of zero-length records on the rx_listEPSS 2.9%KEVCVE-2024-36971HIGHnet: fix __dst_negative_advice() raceEPSS 2.7%KEVCVE-2024-53150HIGHALSA: usb-audio: Fix out of bounds reads when finding clock sourcesEPSS 1.4%KEV
References
https://git.kernel.org/stable/c/330f2936ab768c7215322a476f033143e8891d28https://git.kernel.org/stable/c/342632a4d8ba3fafc1556deee0b7a48dd7860336https://git.kernel.org/stable/c/3e03f1209c1c8a45a7bc559f4ecd79d9b33f706dhttps://git.kernel.org/stable/c/5626785b0e4665326e4d96736c106161da09b2f0https://git.kernel.org/stable/c/6f6a5b0b0a84c2de0e152f2841e57bc226db924fhttps://git.kernel.org/stable/c/7d221859ba45d7228d0138c9a3e55bd3bb31e14ehttps://git.kernel.org/stable/c/8eca0f85eeb0789be40e637bcf9a21c4265b6c6fhttps://git.kernel.org/stable/c/ffc27411ea60b8a09f1fea3d664b65210fdeb454