CVE-2026-89878
Last modified
CVE-2026-89878 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: media: s2255: check firmware size before reading trailing marker s2255_probe() reads a 4-byte marker and version from the last 8 bytes of the firmware blob (fw->data[fw_size - 8] and [fw_size - 4]). If the firmware file is shorter than 8 bytes, fw_size - 8 underflows and the access reads out of bounds.
Description
In the Linux kernel, the following vulnerability has been resolved: media: s2255: check firmware size before reading trailing marker s2255_probe() reads a 4-byte marker and version from the last 8 bytes of the firmware blob (fw->data[fw_size - 8] and [fw_size - 4]). If the firmware file is shorter than 8 bytes, fw_size - 8 underflows and the access reads out of bounds. Validate the firmware size before indexing.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 14d962602c8bf86e63c9b9272be1f0360d0a448a, < 6f6a5b0b0a84c2de0e152f2841e57bc226db924f; >= 14d962602c8bf86e63c9b9272be1f0360d0a448a, < 8eca0f85eeb0789be40e637bcf9a21c4265b6c6f; >= 14d962602c8bf86e63c9b9272be1f0360d0a448a, < ffc27411ea60b8a09f1fea3d664b65210fdeb454; >= 14d962602c8bf86e63c9b9272be1f0360d0a448a, < 5626785b0e4665326e4d96736c106161da09b2f0; >= 14d962602c8bf86e63c9b9272be1f0360d0a448a, < 3e03f1209c1c8a45a7bc559f4ecd79d9b33f706d; >= 14d962602c8bf86e63c9b9272be1f0360d0a448a, < 342632a4d8ba3fafc1556deee0b7a48dd7860336; >= 14d962602c8bf86e63c9b9272be1f0360d0a448a, < 7d221859ba45d7228d0138c9a3e55bd3bb31e14e; >= 14d962602c8bf86e63c9b9272be1f0360d0a448a, < 330f2936ab768c7215322a476f033143e8891d28 |
| Linux | Linux | 2.6.28 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-89878?
How severe is CVE-2026-89878?
How do I fix CVE-2026-89878?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-89872In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89873In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89874In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89875In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89876In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89877In the Linux kernel, the following vulnerability has been re…8.4
- CVE-2026-89879In the Linux kernel, the following vulnerability has been re…
- CVE-2026-8988Autel Maxi Charger Single firmware through V1.03.51 exposes …6.8
- CVE-2026-89880In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89881In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89882In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89883In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2026-89878?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
