Impact
In the Linux kernel, the helper function ucs2_strnlen() performs an off‑by‑one out‑of‑bounds read. The routine reads the current UCS‑2 character before verifying that the caller‑supplied maximum length has been reached; if the input string is not NUL‑terminated within that bound, the loop can read one UCS‑2 character past the limit, exposing kernel memory contents to a read operation data from the kernel address space where the function executes.
Affected Systems
All Linux kernel implementations that include the predecessor of the patched lib/ucs2_string.c code are affected. The advisory does not specify a version range, so any kernel that lacks the CVE‑2026‑89726 fix is potentially vulnerable and should be examined for the presence of the original ucs2_strnlen() implementation.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1 % reflects a very low expected exploitation likelihood, and the vulnerability is not listed in CISA’s KEV catalog. No public exploits are currently known. Based on the description, the likely attack vector is local: execute code in kernel space or influence kernel functions that invoke ucs2_strnlen() with crafted input. Overall, the risk is moderate with low probability of exploitation in the wild.
OpenCVE Enrichment
Debian DSA