Out-of-bounds read in Linux kernel - CVE-2026-89726
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to read memory beyond the specified length.
The vulnerability exists due to an off-by-one out-of-bounds read in ucs2_strnlen() in lib/ucs2_string.c when processing a UCS-2 string that is not NUL-terminated within the caller-provided maximum length. A local user can supply a non-NUL-terminated UCS-2 string to read memory beyond the specified length.