SB2026091780 - Out-of-bounds write in Linux kernel usb s2255 driver
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2026-89879)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to write beyond the destination buffer.
The vulnerability exists due to an out-of-bounds write in the s2255_fillbuff() JPEG/MJPEG frame handling code when processing a device-supplied JPEG frame header. An attacker with physical access can provide a crafted frame header with an oversized jpg_size value to write beyond the destination buffer.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2542516a147bfad740e7e411c251b639fad260ff
- https://git.kernel.org/stable/c/32a595dd3e8634544e5cfbc47f906dff3d3c1ef8
- https://git.kernel.org/stable/c/4b6f7bccc6559ae5c54573c284fe76eafc9989b2
- https://git.kernel.org/stable/c/68d664f1b4efe525e99154b7058fcb0378bdaff7
- https://git.kernel.org/stable/c/79f58f900dd221ab04ea74bf4eaf79fa3b0fcc77
- https://git.kernel.org/stable/c/d2ecaaab6a4f165abb54cdf61be60030b5782bf8
- https://git.kernel.org/stable/c/dd739517560c8d0ec4463a53e717bf40b988d7da
- https://git.kernel.org/stable/c/e504cc888f42999dd76b6a43788c422610f2aad2