Executive brief
A utility function in the Linux kernel's character string library contained an off-by-one error that could read one byte past an allocated buffer. Although exploitability is limited, this type of memory safety issue can potentially leak kernel data or contribute to denial of service in edge cases. The fix reorders condition checks to prevent the out-of-bounds access.
Technical details
The vulnerability is a classic off-by-one out-of-bounds read in lib/ucs2_string.c's ucs2_strnlen() function. The function checks the dereferenced character (`*s++ != 0`) before validating that the loop has not exceeded the caller-supplied maximum length. If input is not NUL-terminated within the bound, the loop reads one ucs2_char_t past the limit. The fix reorders the condition to test `length < maxlength` first, preventing dereference beyond bounds. Attack vector is local/kernel-context only; this affects kernel code paths that call ucs2_strnlen() with untrusted or unvalidated length parameters.
Affected products
- Linux Linux kernel 2.6.12 and later
Timeline
- 2026-09-11: disclosed: CVE-2026-89726 published
- 2026-09-07: patched: Fix merged into stable tree