CVE-2026-89726

Updated on 11 Sep 2026

Severity

Awaiting Analysis

Details

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved:

lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()

Patch series “lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()”, v2.

This series fixes an off-by-one out-of-bounds read in ucs2_strnlen().

The first patch is the real fix, the second patch comes as a bonus and fixes the code indentation.

This patch (of 2):

ucs2_strnlen() checks the current character before checking whether the caller-provided maximum length has been reached. If the input is not NUL-terminated within that bound, the loop can read one ucs2_char_t past the limit.

Test the length before dereferencing to prevent an off-by-one out-of-bounds read.

Details

Affected packages:
linux @ 5.4.0 (+4 more)

Fixes