CVE-2026-92477

Summary

In the Linux kernel, the following vulnerability has been resolved:

scsi: ufs: debugfs: Reserve space for a string terminator

ufs_saved_err_write() copies user input into a zero-initialized stack buffer and passes it to kstrtoint(). A write that fills the entire buffer overwrites its only terminator.

Reject an input whose length leaves no room for the trailing NUL.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux7340faae947400907e5e7581444712110d2811d5 < b43890843e834300f967c69e74c7c2eb22cb1664affected
LinuxLinux7340faae947400907e5e7581444712110d2811d5 < 587be18e0935632ebd367b0f89e37aa5762e400faffected
LinuxLinux7340faae947400907e5e7581444712110d2811d5 < d223989e1a1edad217b673486b093bd157fb6c9aaffected
LinuxLinux7340faae947400907e5e7581444712110d2811d5 < cc92af8cc0e4dacd4375d34475141b0f1a70c09eaffected
LinuxLinux7340faae947400907e5e7581444712110d2811d5 < 2b3fb5693c25c21741f357a8c9d0e1f19b7e368faffected
LinuxLinux7340faae947400907e5e7581444712110d2811d5 < abd26e6b53c4169122d61fdd4cabe09bdd916aacaffected
LinuxLinux5.16affected
LinuxLinux0 < 5.16unaffected
LinuxLinux6.1.188 <= 6.1.*unaffected
LinuxLinux6.6.157 <= 6.6.*unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References