[merged mm-nonmm-stable] lib-ucs2_stringc-fix-out-of-bounds-read-in-ucs2_strnlen.patch removed from -mm tree
Andrew Morton <[email protected]> Mon, 03 Aug 2026 21:05:54 -0700
| Newsgroups | org.kernel.vger.stable,org.kernel.vger.mm-commits |
|---|---|
| Message-ID | <[email protected]> |
The quilt patch titled
Subject: lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()
has been removed from the -mm tree. Its filename was
lib-ucs2_stringc-fix-out-of-bounds-read-in-ucs2_strnlen.patch
This patch was dropped because it was merged into the mm-nonmm-stable branch
of git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm
------------------------------------------------------
From: Vincent Mailhol <[email protected]>
Subject: lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()
Date: Thu, 23 Jul 2026 21:40:31 +0200
Patch series "lib/ucs2_string.c: fix out-of-bounds read in
ucs2_strnlen()", v2.
This series fixes an off-by-one out-of-bounds read in ucs2_strnlen().
The first patch is the real fix, the second patch comes as a bonus and
fixes the code indentation.
This patch (of 2):
ucs2_strnlen() checks the current character before checking whether the
caller-provided maximum length has been reached. If the input is not
NUL-terminated within that bound, the loop can read one ucs2_char_t past
the limit.
Test the length before dereferencing to prevent an off-by-one
out-of-bounds read.
Link: https://lore.kernel.org/[email protected]
Link: https://lore.kernel.org/[email protected]
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Vincent Mailhol <[email protected]>
Cc: Kees Cook <[email protected]>
Cc: <[email protected]>
Signed-off-by: Andrew Morton <[email protected]>
---
lib/ucs2_string.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/lib/ucs2_string.c~lib-ucs2_stringc-fix-out-of-bounds-read-in-ucs2_strnlen
+++ a/lib/ucs2_string.c
@@ -8,7 +8,7 @@ ucs2_strnlen(const ucs2_char_t *s, size_
{
unsigned long length = 0;
- while (*s++ != 0 && length < maxlength)
+ while (length < maxlength && *s++ != 0)
length++;
return length;
}
_
Patches currently in -mm which might be from [email protected] are