CVE-2026-89726

Summary

In the Linux kernel, the following vulnerability has been resolved:

lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()

Patch series "lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()", v2.

This series fixes an off-by-one out-of-bounds read in ucs2_strnlen().

The first patch is the real fix, the second patch comes as a bonus and fixes the code indentation.

This patch (of 2):

ucs2_strnlen() checks the current character before checking whether the caller-provided maximum length has been reached. If the input is not NUL-terminated within that bound, the loop can read one ucs2_char_t past the limit.

Test the length before dereferencing to prevent an off-by-one out-of-bounds read.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 709eb41adaf78d59d4579a13a898125919b69bccaffected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7d658da725ea81c91f73087547b97e7ced82d62baffected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1b0dc3cbb8630f0b5cb34d848628225920a904beaffected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < cec0d03fe785380540dc1b4d07c80f67ae2ffc78affected
LinuxLinux2.6.12affected
LinuxLinux0 < 2.6.12unaffected
LinuxLinux6.12.109 <= 6.12.*unaffected
LinuxLinux6.18.50 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References