Description
In the Linux kernel, the following vulnerability has been resolved:

media: s2255: bound JPEG frame size before copying into the buffer

s2255_fillbuff() memcpy()s vc->jpg_size bytes of a captured JPEG/MJPEG
frame into the vb2 plane. vc->jpg_size is taken verbatim from the
S2255_MARKER_FRAME header the device sends (pdword[4] in save_frame())
and, unlike the frame payload length just above it, is never bounded:

payload = le32_to_cpu(pdword[3]);
if (payload > vc->req_image_size) /* payload is checked ... */
return -EINVAL;
vc->pkt_size = payload;
vc->jpg_size = le32_to_cpu(pdword[4]); /* ... jpg_size is not */

A malicious or malfunctioning device can therefore report a jpg_size
larger than the destination vb2 plane, and the memcpy() writes past it.
jpg_size is a signed int, so a value with the top bit set also turns
into a huge length.

Reject a frame whose jpg_size is negative or exceeds the plane size
before copying it.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption
Action: Immediate Patch
AI Analysis

Impact

A kernel driver for S2255 camera devices fails to check the reported JPEG frame size before copying data into a kernel buffer. The driver reads a size field from a device‐supplied header and passes it directly to memcpy. An attacker can supply a negative or excessively large size, causing a buffer overflow that corrupts kernel memory and could lead to arbitrary code execution or privilege escalation. The weakness is a classic unchecked memory copy problem captured by CWE‑119.

Affected Systems

The vulnerability exists in the Linux kernel’s media subsystem, specifically the s2255 driver. No specific kernel versions are listed, so affected releases are those that have not yet incorporated the patch. All machines that load the s2255 driver and process JPEG/MJPEG frames are potentially impacted.

Risk and Exploitability

The EPSS score indicates a very low likelihood of exploitation. Because the flaw is triggered by data sent from an external media device, an attacker would need the ability to control or spoof the device’s communication, suggesting a local or device‑based attack surface. The vulnerability has no listing in CISA’s KEV catalog, and no high CVSS score is provided, so while the technical impact is severe, the practical risk is modest until the device can be compromised.

Generated by OpenCVE AI on September 18, 2026 at 03:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the s2255 driver fix.
  • If an immediate kernel update is not feasible, remove or disable the s2255 driver module and block access to the S2255 device from untrusted users.
  • Configure device access controls (e.g., using udev rules or capabilities) to limit which users can use the /dev/v4l* devices until the kernel upgrade is applied.

Generated by OpenCVE AI on September 18, 2026 at 03:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: s2255: bound JPEG frame size before copying into the buffer s2255_fillbuff() memcpy()s vc->jpg_size bytes of a captured JPEG/MJPEG frame into the vb2 plane. vc->jpg_size is taken verbatim from the S2255_MARKER_FRAME header the device sends (pdword[4] in save_frame()) and, unlike the frame payload length just above it, is never bounded: payload = le32_to_cpu(pdword[3]); if (payload > vc->req_image_size) /* payload is checked ... */ return -EINVAL; vc->pkt_size = payload; vc->jpg_size = le32_to_cpu(pdword[4]); /* ... jpg_size is not */ A malicious or malfunctioning device can therefore report a jpg_size larger than the destination vb2 plane, and the memcpy() writes past it. jpg_size is a signed int, so a value with the top bit set also turns into a huge length. Reject a frame whose jpg_size is negative or exceeds the plane size before copying it.
Title media: s2255: bound JPEG frame size before copying into the buffer
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:45.564Z

Reserved: 2026-09-11T19:38:34.772Z

Link: CVE-2026-89879

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:56.230

Modified: 2026-09-16T11:16:56.230

Link: CVE-2026-89879

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:15:02Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer