{"id":"CVE-2026-89878","published":"2026-09-16T11:16:56.100","lastModified":"2026-09-16T11:16:56.100","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: s2255: check firmware size before reading trailing marker\n\ns2255_probe() reads a 4-byte marker and version from the last 8 bytes\nof the firmware blob (fw->data[fw_size - 8] and [fw_size - 4]). If the\nfirmware file is shorter than 8 bytes, fw_size - 8 underflows and the\naccess reads out of bounds. Validate the firmware size before indexing.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/330f2936ab768c7215322a476f033143e8891d28","tags":[]},{"url":"https://git.kernel.org/stable/c/342632a4d8ba3fafc1556deee0b7a48dd7860336","tags":[]},{"url":"https://git.kernel.org/stable/c/3e03f1209c1c8a45a7bc559f4ecd79d9b33f706d","tags":[]},{"url":"https://git.kernel.org/stable/c/5626785b0e4665326e4d96736c106161da09b2f0","tags":[]},{"url":"https://git.kernel.org/stable/c/6f6a5b0b0a84c2de0e152f2841e57bc226db924f","tags":[]},{"url":"https://git.kernel.org/stable/c/7d221859ba45d7228d0138c9a3e55bd3bb31e14e","tags":[]},{"url":"https://git.kernel.org/stable/c/8eca0f85eeb0789be40e637bcf9a21c4265b6c6f","tags":[]},{"url":"https://git.kernel.org/stable/c/ffc27411ea60b8a09f1fea3d664b65210fdeb454","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}