Out-of-bounds write in Linux kernel - CVE-2026-89879
Published: September 17, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to write beyond the destination buffer.
The vulnerability exists due to an out-of-bounds write in the s2255_fillbuff() JPEG/MJPEG frame handling code when processing a device-supplied JPEG frame header. An attacker with physical access can provide a crafted frame header with an oversized jpg_size value to write beyond the destination buffer.
Affected software
How to mitigate CVE-2026-89879
External References
- https://git.kernel.org/stable/c/2542516a147bfad740e7e411c251b639fad260ff
- https://git.kernel.org/stable/c/32a595dd3e8634544e5cfbc47f906dff3d3c1ef8
- https://git.kernel.org/stable/c/4b6f7bccc6559ae5c54573c284fe76eafc9989b2
- https://git.kernel.org/stable/c/68d664f1b4efe525e99154b7058fcb0378bdaff7
- https://git.kernel.org/stable/c/79f58f900dd221ab04ea74bf4eaf79fa3b0fcc77
- https://git.kernel.org/stable/c/d2ecaaab6a4f165abb54cdf61be60030b5782bf8
- https://git.kernel.org/stable/c/dd739517560c8d0ec4463a53e717bf40b988d7da
- https://git.kernel.org/stable/c/e504cc888f42999dd76b6a43788c422610f2aad2