-

CVE-2026-89879

media: s2255: bound JPEG frame size before copying into the buffer

In the Linux kernel, the following vulnerability has been resolved:

media: s2255: bound JPEG frame size before copying into the buffer

s2255_fillbuff() memcpy()s vc->jpg_size bytes of a captured JPEG/MJPEG
frame into the vb2 plane.  vc->jpg_size is taken verbatim from the
S2255_MARKER_FRAME header the device sends (pdword[4] in save_frame())
and, unlike the frame payload length just above it, is never bounded:

	payload = le32_to_cpu(pdword[3]);
	if (payload > vc->req_image_size)	/* payload is checked ... */
		return -EINVAL;
	vc->pkt_size = payload;
	vc->jpg_size = le32_to_cpu(pdword[4]);	/* ... jpg_size is not */

A malicious or malfunctioning device can therefore report a jpg_size
larger than the destination vb2 plane, and the memcpy() writes past it.
jpg_size is a signed int, so a value with the top bit set also turns
into a huge length.

Reject a frame whose jpg_size is negative or exceeds the plane size
before copying it.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 38f993ad8b1fe4caf9e989caf6e2a25aff3bbaf7
Version < 32a595dd3e8634544e5cfbc47f906dff3d3c1ef8
Status affected
Version 38f993ad8b1fe4caf9e989caf6e2a25aff3bbaf7
Version < 4b6f7bccc6559ae5c54573c284fe76eafc9989b2
Status affected
Version 38f993ad8b1fe4caf9e989caf6e2a25aff3bbaf7
Version < 2542516a147bfad740e7e411c251b639fad260ff
Status affected
Version 38f993ad8b1fe4caf9e989caf6e2a25aff3bbaf7
Version < 79f58f900dd221ab04ea74bf4eaf79fa3b0fcc77
Status affected
Version 38f993ad8b1fe4caf9e989caf6e2a25aff3bbaf7
Version < d2ecaaab6a4f165abb54cdf61be60030b5782bf8
Status affected
Version 38f993ad8b1fe4caf9e989caf6e2a25aff3bbaf7
Version < 68d664f1b4efe525e99154b7058fcb0378bdaff7
Status affected
Version 38f993ad8b1fe4caf9e989caf6e2a25aff3bbaf7
Version < dd739517560c8d0ec4463a53e717bf40b988d7da
Status affected
Version 38f993ad8b1fe4caf9e989caf6e2a25aff3bbaf7
Version < e504cc888f42999dd76b6a43788c422610f2aad2
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.27
Status affected
Version 0
Version < 2.6.27
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.117
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/32a595dd3e8634544e5cfbc47f906dff3d3c1ef8
https://git.kernel.org/stable/c/4b6f7bccc6559ae5c54573c284fe76eafc9989b2
https://git.kernel.org/stable/c/2542516a147bfad740e7e411c251b639fad260ff
https://git.kernel.org/stable/c/79f58f900dd221ab04ea74bf4eaf79fa3b0fcc77
https://git.kernel.org/stable/c/d2ecaaab6a4f165abb54cdf61be60030b5782bf8
https://git.kernel.org/stable/c/68d664f1b4efe525e99154b7058fcb0378bdaff7
https://git.kernel.org/stable/c/dd739517560c8d0ec4463a53e717bf40b988d7da
https://git.kernel.org/stable/c/e504cc888f42999dd76b6a43788c422610f2aad2