Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: ufs: debugfs: Reserve space for a string terminator

ufs_saved_err_write() copies user input into a zero-initialized stack
buffer and passes it to kstrtoint(). A write that fills the entire buffer
overwrites its only terminator.

Reject an input whose length leaves no room for the trailing NUL.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply patch
AI Analysis

Impact

The flaw arises when user supplied data is copied into a small, zero‑initialized stack buffer in the UFS driver without reserving space for the terminating NUL byte. If the input length exactly matches the buffer size, the single terminator is overwritten. The subsequent conversion to an integer via kstrtoint() then reads past the buffer boundary, which can cause a kernel panic or potentially expose adjacent kernel memory to a locally privileged user. The vulnerability does not provide remote code execution, but it can lead to a crash and loss of service.

Affected Systems

All Linux kernel binaries released before the embedded fix are affected, because the vendor is generic Linux and the product is the kernel itself. The CVE does not provide a specific version range, so any kernel that has not yet been patched to include the input‑length validation and terminator reservation is considered vulnerable. This includes all distributions that ship the unmodified UFS driver and expose the offending debugfs entry.

Risk and Exploitability

The EPSS score of less than 1 % indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is local via the debugfs interface, which typically requires root or elevated capabilities to write to the node. A local attacker who can write to the affected debugfs entry may trigger a kernel panic, resulting in a denial of service. The CVSS score is not explicitly provided, but the impact is sufficient to warrant prompt patching for systems that enable or rely on the debugfs functionality.

Generated by OpenCVE AI on September 19, 2026 at 13:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that includes the input‑length validation and terminator reservation fix.
  • If the UFS driver’s debugfs functionality is not required, disable the debugfs entry or unmount the debugfs filesystem and restrict its permissions so that only the root user can access it.
  • Apply an SELinux or AppArmor policy that explicitly denies write access to the UFS debugfs node for all non‑privileged processes.

Generated by OpenCVE AI on September 19, 2026 at 13:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: debugfs: Reserve space for a string terminator ufs_saved_err_write() copies user input into a zero-initialized stack buffer and passes it to kstrtoint(). A write that fills the entire buffer overwrites its only terminator. Reject an input whose length leaves no room for the trailing NUL.
Title scsi: ufs: debugfs: Reserve space for a string terminator
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:55.741Z

Reserved: 2026-09-16T12:21:13.870Z

Link: CVE-2026-92477

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:49.720

Modified: 2026-09-17T17:17:49.720

Link: CVE-2026-92477

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:30:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer