[merged mm-nonmm-stable] lib-ucs2_stringc-fix-out-of-bounds-read-in-ucs2_strnlen.patch removed from -mm tree

Andrew Morton <[email protected]> Mon, 03 Aug 2026 21:05:54 -0700
Newsgroups org.kernel.vger.stable,org.kernel.vger.mm-commits
Message-ID <[email protected]>
The quilt patch titled
     Subject: lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()
has been removed from the -mm tree.  Its filename was
     lib-ucs2_stringc-fix-out-of-bounds-read-in-ucs2_strnlen.patch

This patch was dropped because it was merged into the mm-nonmm-stable branch
of git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm

------------------------------------------------------
From: Vincent Mailhol <[email protected]>
Subject: lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()
Date: Thu, 23 Jul 2026 21:40:31 +0200

Patch series "lib/ucs2_string.c: fix out-of-bounds read in
ucs2_strnlen()", v2.

This series fixes an off-by-one out-of-bounds read in ucs2_strnlen().

The first patch is the real fix, the second patch comes as a bonus and
fixes the code indentation.


This patch (of 2):

ucs2_strnlen() checks the current character before checking whether the
caller-provided maximum length has been reached.  If the input is not
NUL-terminated within that bound, the loop can read one ucs2_char_t past
the limit.

Test the length before dereferencing to prevent an off-by-one
out-of-bounds read.

Link: https://lore.kernel.org/[email protected]
Link: https://lore.kernel.org/[email protected]
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Vincent Mailhol <[email protected]>
Cc: Kees Cook <[email protected]>
Cc: <[email protected]>
Signed-off-by: Andrew Morton <[email protected]>
---

 lib/ucs2_string.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/lib/ucs2_string.c~lib-ucs2_stringc-fix-out-of-bounds-read-in-ucs2_strnlen
+++ a/lib/ucs2_string.c
@@ -8,7 +8,7 @@ ucs2_strnlen(const ucs2_char_t *s, size_
 {
         unsigned long length = 0;
 
-        while (*s++ != 0 && length < maxlength)
+	while (length < maxlength && *s++ != 0)
                 length++;
         return length;
 }
_

Patches currently in -mm which might be from [email protected] are