---
id: CVE-2026-92480
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  scsi: ufs: core: Validate string descriptors

  The string descriptor length includes a two-byte header while the UTF-16
  payload starts after it
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  scsi: ufs: core: Validate string descriptors

  The string descriptor length includes a two-byte header while the UTF-16
  payload starts after it. utf16s_to_utf8s() expect…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 4b828fe156a662a4b6135019bf077040340f299b <
    66da25277256b6bf4c3fdbf3c9bfd43324c9cf25
  - >-
    Linux >= 4b828fe156a662a4b6135019bf077040340f299b <
    d96e83d028d7d8762e424e49c671d49ac2ecf14f
  - Linux 5.4
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:17:50.053'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92480'
references:
  - url: 'https://git.kernel.org/stable/c/66da25277256b6bf4c3fdbf3c9bfd43324c9cf25'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d96e83d028d7d8762e424e49c671d49ac2ecf14f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.788Z'
epss: 0.00198
epssPercentile: 0.0848
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

scsi: ufs: core: Validate string descriptors

The string descriptor length includes a two-byte header while the UTF-16
payload starts after it. utf16s_to_utf8s() expects a count of UTF-16 code
units, not bytes. Passing the payload byte count can make it read beyond
the descriptor buffer.

Validate that the payload has an even byte count, pass a code-unit count to
the converter, and allocate sufficient UTF-8 output space.

The raw string buffer starts after the descriptor header but its size is
bLength. Copying bLength bytes from that pointer can read beyond the
response buffer.

Allocate a zeroed bLength-sized buffer and copy only the UTF-16
payload. This preserves the raw buffer size consumed by the RPMB device-ID
ABI while avoiding the overread.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
