CVE-2026-89878
Published Sep 16, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: media: s2255: check firmware size before reading trailing marker s2255_probe() reads a 4-byte marker and version from the last 8 bytes of the firmware blob (fw->data[fw_size - 8] and [fw_size - 4]). If the firmware file is shorter than 8 bytes, fw_size - 8 underflows and the access reads out of bounds. Validate the firmware size before indexing.
Is your site exposed to CVE-2026-89878?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/330f2936ab768c7215322a476f033143e8891d28
https://git.kernel.org/stable/c/342632a4d8ba3fafc1556deee0b7a48dd7860336
https://git.kernel.org/stable/c/3e03f1209c1c8a45a7bc559f4ecd79d9b33f706d
https://git.kernel.org/stable/c/5626785b0e4665326e4d96736c106161da09b2f0
https://git.kernel.org/stable/c/6f6a5b0b0a84c2de0e152f2841e57bc226db924f
https://git.kernel.org/stable/c/7d221859ba45d7228d0138c9a3e55bd3bb31e14e
https://git.kernel.org/stable/c/8eca0f85eeb0789be40e637bcf9a21c4265b6c6f
https://git.kernel.org/stable/c/ffc27411ea60b8a09f1fea3d664b65210fdeb454
Frequently Asked Questions
What is CVE-2026-89878? +
In the Linux kernel, the following vulnerability has been resolved:
media: s2255: check firmware size before reading trailing marker
s2255_probe() reads a 4-byte marker and version from the last 8 bytes
of the firmware blob (fw->data[fw_size - 8] and [fw_size - 4]). If the
firmware file is shorter than 8 bytes, fw_size - 8 underflows and the
access reads out of bounds. Validate the firmware size before indexing.
How do I check if I'm vulnerable to CVE-2026-89878? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.