« Volver al listado

CVE-2026-89726

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()

Patch series "lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()", v2.

This series fixes an off-by-one out-of-bounds read in ucs2_strnlen().

The first patch is the real fix, the second patch comes as a bonus and fixes the code indentation.

This patch (of 2):

ucs2_strnlen() checks the current character before checking whether the caller-provided maximum length has been reached. If the input is not NUL-terminated within that bound, the loop can read one ucs2_char_t past the limit.

Leer descripción completaMostrar menos

Test the length before dereferencing to prevent an off-by-one out-of-bounds read.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89726",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "lessThan": "04ae68af4107600120c3c41c94268f43bc350d48",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "lessThan": "2e5a70a175f0c74e7238b013a96c4eabc3002934",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "lessThan": "3ada20e110bf3245edb0a3bcddadc33d0f142f8d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "lessThan": "60c74f42f5abddb85dd919b4448d5474e65dbe76",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "lessThan": "709eb41adaf78d59d4579a13a898125919b69bcc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "lessThan": "7d658da725ea81c91f73087547b97e7ced82d62b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "lessThan": "1b0dc3cbb8630f0b5cb34d848628225920a904be",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "lessThan": "cec0d03fe785380540dc1b4d07c80f67ae2ffc78",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "lib/ucs2_string.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.12"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.12",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.270",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.109",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.50",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "lib/ucs2_string.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:20:02.907",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/04ae68af4107600120c3c41c94268f43bc350d48",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1b0dc3cbb8630f0b5cb34d848628225920a904be",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2e5a70a175f0c74e7238b013a96c4eabc3002934",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3ada20e110bf3245edb0a3bcddadc33d0f142f8d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/60c74f42f5abddb85dd919b4448d5474e65dbe76",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/709eb41adaf78d59d4579a13a898125919b69bcc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7d658da725ea81c91f73087547b97e7ced82d62b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cec0d03fe785380540dc1b4d07c80f67ae2ffc78",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()\n\nPatch series \"lib/ucs2_string.c: fix out-of-bounds read in\nucs2_strnlen()\", v2.\n\nThis series fixes an off-by-one out-of-bounds read in ucs2_strnlen().\n\nThe first patch is the real fix, the second patch comes as a bonus and\nfixes the code indentation.\n\n\nThis patch (of 2):\n\nucs2_strnlen() checks the current character before checking whether the\ncaller-provided maximum length has been reached.  If the input is not\nNUL-terminated within that bound, the loop can read one ucs2_char_t past\nthe limit.\n\nTest the length before dereferencing to prevent an off-by-one\nout-of-bounds read."
    }
  ],
  "lastModified": "2026-09-14T13:19:21.893",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}