Improper Null Termination in Linux kernel - CVE-2026-89817
Published: September 17, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to perform an out-of-bounds read.
The vulnerability exists due to improper null termination in gud_connector_add_tv_mode() when processing TV mode names received from a USB device. An attacker with physical access can provide TV mode names that are not NUL-terminated to perform an out-of-bounds read.
Affected software
How to mitigate CVE-2026-89817
External References
- https://git.kernel.org/stable/c/08c8ec28547987e55a90c662f8795e05c2925498
- https://git.kernel.org/stable/c/500cb24cd61bad8a2747ddfc49b7034899c82d94
- https://git.kernel.org/stable/c/6ea61f1d4cbaa0db937e31bffc041fb8afeacf52
- https://git.kernel.org/stable/c/89210cb5ff8fdbe055c97ac688be2268f6c815ae
- https://git.kernel.org/stable/c/9096edfd6f2edbc79612b482547e0972edbcfe4b
- https://git.kernel.org/stable/c/b86438a5c6b0250ccb07dd380184d1e70e0dea6c
- https://git.kernel.org/stable/c/d0f3312f7800eb0e00d1264f66104c788f43dd69