CVE-2026-89878

Source
https://cve.org/CVERecord?id=CVE-2026-89878
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89878.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89878
Downstream
Published
2026-09-16T10:31:44Z
Modified
2026-09-18T03:48:33Z
Summary
media: s2255: check firmware size before reading trailing marker
Details

In the Linux kernel, the following vulnerability has been resolved:

media: s2255: check firmware size before reading trailing marker

s2255_probe() reads a 4-byte marker and version from the last 8 bytes of the firmware blob (fw->data[fw_size - 8] and [fw_size - 4]). If the firmware file is shorter than 8 bytes, fw_size - 8 underflows and the access reads out of bounds. Validate the firmware size before indexing.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89878.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
14d962602c8bf86e63c9b9272be1f0360d0a448a
Fixed
6f6a5b0b0a84c2de0e152f2841e57bc226db924f
Fixed
8eca0f85eeb0789be40e637bcf9a21c4265b6c6f
Fixed
ffc27411ea60b8a09f1fea3d664b65210fdeb454
Fixed
5626785b0e4665326e4d96736c106161da09b2f0
Fixed
3e03f1209c1c8a45a7bc559f4ecd79d9b33f706d
Fixed
342632a4d8ba3fafc1556deee0b7a48dd7860336
Fixed
7d221859ba45d7228d0138c9a3e55bd3bb31e14e
Fixed
330f2936ab768c7215322a476f033143e8891d28

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89878.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.28
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89878.json"