CVE-2026-89726Medium· 5.5▾ SunlitA flaw was found in the Linux kernel's `ucs2_strnlen()` function. This vulnerability occurs because the function checks the current character before verifying if the maximum allowed length has been reached. If the input string is not prope…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 5.3
none → medium
— → 5.3
none → medium
0.2% → 0.2%
— → 5.3
none → medium
Last analysed / modified upstream
5.3 → 5.5
A flaw was found in the Linux kernel's ucs2_strnlen() function. This vulnerability occurs because the function checks the current character before verifying if the maximum allowed length has been reached. If the input string is not properly terminated within the specified bounds, an attacker could potentially trigger an out-of-bounds read, which may lead to information disclosure or a denial of service.
kernel: lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-21.
Affected:
No fix planned:
Not affected:
Fix deferred
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-80985High· 7.0kernel: net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry (CVE-2026-80985)
CVE-2026-80969Medium· 5.5kernel: ALSA: mpu401: Check card index validity at probe (CVE-2026-80969)
CVE-2026-80972Medium· 5.5kernel: ALSA: aloop: Check card index validity at probe (CVE-2026-80972)
CVE-2026-80973High· 7.0kernel: ALSA: 6fire: bound the MIDI event length from the device (CVE-2026-80973)
CVE-2026-80976High· 7.0kernel: seg6: reset IP6CB after IPv6 decapsulation (CVE-2026-80976)
CVE-2026-89443Medium· 5.5kernel: platform/x86: ISST: Validate level in perf mask ioctls (CVE-2026-89443)