-
CVE-2026-89726
- EPSS 0.17%
- Veröffentlicht 11.09.2026 19:46:37
- Zuletzt bearbeitet 14.09.2026 13:19:21
- Erkennungen
lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()
In the Linux kernel, the following vulnerability has been resolved: lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() Patch series "lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()", v2. This series fixes an off-by-one out-of-bounds read in ucs2_strnlen(). The first patch is the real fix, the second patch comes as a bonus and fixes the code indentation. This patch (of 2): ucs2_strnlen() checks the current character before checking whether the caller-provided maximum length has been reached. If the input is not NUL-terminated within that bound, the loop can read one ucs2_char_t past the limit. Test the length before dereferencing to prevent an off-by-one out-of-bounds read.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
04ae68af4107600120c3c41c94268f43bc350d48
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
2e5a70a175f0c74e7238b013a96c4eabc3002934
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
3ada20e110bf3245edb0a3bcddadc33d0f142f8d
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
60c74f42f5abddb85dd919b4448d5474e65dbe76
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
709eb41adaf78d59d4579a13a898125919b69bcc
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
7d658da725ea81c91f73087547b97e7ced82d62b
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
1b0dc3cbb8630f0b5cb34d848628225920a904be
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
cec0d03fe785380540dc1b4d07c80f67ae2ffc78
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
2.6.12
Status
affected
Version
0
Version <
2.6.12
Status
unaffected
Version <=
5.10.*
Version
5.10.270
Status
unaffected
Version <=
5.15.*
Version
5.15.221
Status
unaffected
Version <=
6.1.*
Version
6.1.188
Status
unaffected
Version <=
6.6.*
Version
6.6.157
Status
unaffected
Version <=
6.12.*
Version
6.12.109
Status
unaffected
Version <=
6.18.*
Version
6.18.50
Status
unaffected
Version <=
7.2.*
Version
7.2.4
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.064 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/709eb41adaf78d59d4579a13a898125919b69bcc
https://git.kernel.org/stable/c/7d658da725ea81c91f73087547b97e7ced82d62b
https://git.kernel.org/stable/c/1b0dc3cbb8630f0b5cb34d848628225920a904be
https://git.kernel.org/stable/c/cec0d03fe785380540dc1b4d07c80f67ae2ffc78
https://git.kernel.org/stable/c/04ae68af4107600120c3c41c94268f43bc350d48
https://git.kernel.org/stable/c/2e5a70a175f0c74e7238b013a96c4eabc3002934
https://git.kernel.org/stable/c/3ada20e110bf3245edb0a3bcddadc33d0f142f8d
https://git.kernel.org/stable/c/60c74f42f5abddb85dd919b4448d5474e65dbe76