Impact
A kernel driver for S2255 camera devices fails to check the reported JPEG frame size before copying data into a kernel buffer. The driver reads a size field from a device‐supplied header and passes it directly to memcpy. An attacker can supply a negative or excessively large size, causing a buffer overflow that corrupts kernel memory and could lead to arbitrary code execution or privilege escalation. The weakness is a classic unchecked memory copy problem captured by CWE‑119.
Affected Systems
The vulnerability exists in the Linux kernel’s media subsystem, specifically the s2255 driver. No specific kernel versions are listed, so affected releases are those that have not yet incorporated the patch. All machines that load the s2255 driver and process JPEG/MJPEG frames are potentially impacted.
Risk and Exploitability
The EPSS score indicates a very low likelihood of exploitation. Because the flaw is triggered by data sent from an external media device, an attacker would need the ability to control or spoof the device’s communication, suggesting a local or device‑based attack surface. The vulnerability has no listing in CISA’s KEV catalog, and no high CVSS score is provided, so while the technical impact is severe, the practical risk is modest until the device can be compromised.
OpenCVE Enrichment
Debian DLA
Debian DSA