-

CVE-2026-92480

scsi: ufs: core: Validate string descriptors

In the Linux kernel, the following vulnerability has been resolved:

scsi: ufs: core: Validate string descriptors

The string descriptor length includes a two-byte header while the UTF-16
payload starts after it. utf16s_to_utf8s() expects a count of UTF-16 code
units, not bytes. Passing the payload byte count can make it read beyond
the descriptor buffer.

Validate that the payload has an even byte count, pass a code-unit count to
the converter, and allocate sufficient UTF-8 output space.

The raw string buffer starts after the descriptor header but its size is
bLength. Copying bLength bytes from that pointer can read beyond the
response buffer.

Allocate a zeroed bLength-sized buffer and copy only the UTF-16
payload. This preserves the raw buffer size consumed by the RPMB device-ID
ABI while avoiding the overread.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 4b828fe156a662a4b6135019bf077040340f299b
Version < 66da25277256b6bf4c3fdbf3c9bfd43324c9cf25
Status affected
Version 4b828fe156a662a4b6135019bf077040340f299b
Version < d96e83d028d7d8762e424e49c671d49ac2ecf14f
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.4
Status affected
Version 0
Version < 5.4
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.051
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/66da25277256b6bf4c3fdbf3c9bfd43324c9cf25
https://git.kernel.org/stable/c/d96e83d028d7d8762e424e49c671d49ac2ecf14f