CVE-2026-89726
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()
Patch series "lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()", v2.
This series fixes an off-by-one out-of-bounds read in ucs2_strnlen().
The first patch is the real fix, the second patch comes as a bonus and fixes the code indentation.
This patch (of 2):
ucs2_strnlen() checks the current character before checking whether the caller-provided maximum length has been reached. If the input is not NUL-terminated within that bound, the loop can read one ucs2_char_t past the limit.
Test the length before dereferencing to prevent an off-by-one out-of-bounds read.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 709eb41adaf78d59d4579a13a898125919b69bcc | affected |
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7d658da725ea81c91f73087547b97e7ced82d62b | affected |
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1b0dc3cbb8630f0b5cb34d848628225920a904be | affected |
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < cec0d03fe785380540dc1b4d07c80f67ae2ffc78 | affected |
| Linux | Linux | 2.6.12 | affected |
| Linux | Linux | 0 < 2.6.12 | unaffected |
| Linux | Linux | 6.12.109 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.50 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.4 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/709eb41adaf78d59d4579a13a898125919b69bcc
- https://git.kernel.org/stable/c/7d658da725ea81c91f73087547b97e7ced82d62b
- https://git.kernel.org/stable/c/1b0dc3cbb8630f0b5cb34d848628225920a904be
- https://git.kernel.org/stable/c/cec0d03fe785380540dc1b4d07c80f67ae2ffc78
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.