Description
In the Linux kernel, the following vulnerability has been resolved:

lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()

Patch series "lib/ucs2_string.c: fix out-of-bounds read in
ucs2_strnlen()", v2.

This series fixes an off-by-one out-of-bounds read in ucs2_strnlen().

The first patch is the real fix, the second patch comes as a bonus and
fixes the code indentation.


This patch (of 2):

ucs2_strnlen() checks the current character before checking whether the
caller-provided maximum length has been reached. If the input is not
NUL-terminated within that bound, the loop can read one ucs2_char_t past
the limit.

Test the length before dereferencing to prevent an off-by-one
out-of-bounds read.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure via Out-of-Bounds Read
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel, the helper function ucs2_strnlen() performs an off‑by‑one out‑of‑bounds read. The routine reads the current UCS‑2 character before verifying that the caller‑supplied maximum length has been reached; if the input string is not NUL‑terminated within that bound, the loop can read one UCS‑2 character past the limit, exposing kernel memory contents to a read operation data from the kernel address space where the function executes.

Affected Systems

All Linux kernel implementations that include the predecessor of the patched lib/ucs2_string.c code are affected. The advisory does not specify a version range, so any kernel that lacks the CVE‑2026‑89726 fix is potentially vulnerable and should be examined for the presence of the original ucs2_strnlen() implementation.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1 % reflects a very low expected exploitation likelihood, and the vulnerability is not listed in CISA’s KEV catalog. No public exploits are currently known. Based on the description, the likely attack vector is local: execute code in kernel space or influence kernel functions that invoke ucs2_strnlen() with crafted input. Overall, the risk is moderate with low probability of exploitation in the wild.

Generated by OpenCVE AI on September 15, 2026 at 20:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that incorporates the CVE‑2026‑89726 patch series.
  • After updating, reboot or reload patching is not possible, enforce strict kernel address space randomization and limit kernel exposure to untrusted data.
  • If a kernel upgrade is not yet available, consider disabling modules or features that depend on ucs2_strnlen() to reduce attack surface.

Generated by OpenCVE AI on September 15, 2026 at 20:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() Patch series "lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()", v2. This series fixes an off-by-one out-of-bounds read in ucs2_strnlen(). The first patch is the real fix, the second patch comes as a bonus and fixes the code indentation. This patch (of 2): ucs2_strnlen() checks the current character before checking whether the caller-provided maximum length has been reached. If the input is not NUL-terminated within that bound, the loop can read one ucs2_char_t past the limit. Test the length before dereferencing to prevent an off-by-one out-of-bounds read.
Title lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:02:17.088Z

Reserved: 2026-09-11T19:38:34.759Z

Link: CVE-2026-89726

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:02.907

Modified: 2026-09-14T13:19:21.893

Link: CVE-2026-89726

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:37Z

Links: CVE-2026-89726 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:45:20Z

Weaknesses