Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: ufs: core: Validate string descriptors

The string descriptor length includes a two-byte header while the UTF-16
payload starts after it. utf16s_to_utf8s() expects a count of UTF-16 code
units, not bytes. Passing the payload byte count can make it read beyond
the descriptor buffer.

Validate that the payload has an even byte count, pass a code-unit count to
the converter, and allocate sufficient UTF-8 output space.

The raw string buffer starts after the descriptor header but its size is
bLength. Copying bLength bytes from that pointer can read beyond the
response buffer.

Allocate a zeroed bLength-sized buffer and copy only the UTF-16
payload. This preserves the raw buffer size consumed by the RPMB device-ID
ABI while avoiding the overread.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure via buffer overread
Action: Apply Patch
AI Analysis

Impact

The Linux kernel contains code that translates USB string descriptors from UTF‑16 to UTF‑8. The translation routine expects a count of UTF‑16 code units, but the implementation mistakenly passes the raw byte count. This causes the routine to read past the end of the descriptor buffer whenever an odd or otherwise incorrect count is supplied. The result is an out‑of‑bounds read that can leak memory contents from the kernel space. The weakness is a classic out‑of‑bounds read (CWE‑125).

Affected Systems

The vulnerability resides in the UFS core driver for SCSI devices and affects all Linux kernel builds that include this code path prior to the patch commit. No specific kernel version range is listed, so every deployment of Linux that enables UFS SCSI support and runs a kernel built from the affected source tree is potentially vulnerable. All Linux distributions that ship such kernels remain in scope.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not in the CISA KEV list, indicating that while the flaw is technically exploitable, there is low evidence of active exploitation. An attacker would need to send a specially crafted SCSI request with a malformed string descriptor to a target device to trigger the buffer overread. This attack requires access to the SCSI device interface, so it is likely limited to local or compromised environments unless the SCSI subsystem is exposed over the network. No known private or public exploits have been reported.

Generated by OpenCVE AI on September 19, 2026 at 05:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that contains the submitted patch by commit 66da252… or use the latest stable release from the distribution’s repository.
  • If an updated kernel is not available immediately, apply the patch locally by pulling the corrected code from the kernel git repository or using the backport patch supplied by the upstream maintainer.
  • Restrict access to SCSI commands that involve UFS string descriptors, for example by disabling UFS support when it is not required or by applying SELinux/AppArmor confinement so that only trusted processes can issue SCSI commands to the device.

Generated by OpenCVE AI on September 19, 2026 at 05:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Validate string descriptors The string descriptor length includes a two-byte header while the UTF-16 payload starts after it. utf16s_to_utf8s() expects a count of UTF-16 code units, not bytes. Passing the payload byte count can make it read beyond the descriptor buffer. Validate that the payload has an even byte count, pass a code-unit count to the converter, and allocate sufficient UTF-8 output space. The raw string buffer starts after the descriptor header but its size is bLength. Copying bLength bytes from that pointer can read beyond the response buffer. Allocate a zeroed bLength-sized buffer and copy only the UTF-16 payload. This preserves the raw buffer size consumed by the RPMB device-ID ABI while avoiding the overread.
Title scsi: ufs: core: Validate string descriptors
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:57.719Z

Reserved: 2026-09-16T12:21:13.870Z

Link: CVE-2026-92480

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:50.053

Modified: 2026-09-17T17:17:50.053

Link: CVE-2026-92480

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T09:30:13Z

Weaknesses