In the Linux kernel, the following vulnerability has been resolved: lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() Patch series "lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()", v2. This series fixes an off-by-one out-of-bounds read in ucs2_strnlen(). The first patch is the real fix, the second patch comes as a bonus and fixes the code indentation. This patch (of 2): ucs2_strnlen() checks the current character before checking whether the caller-provided maximum length has been reached. If the input is not NUL-terminated within that bound, the loop can read one ucs2_char_t past the limit. Test the length before dereferencing to prevent an off-by-one out-of-bounds read.
https://git.kernel.org/stable/c/cec0d03fe785380540dc1b4d07c80f67ae2ffc78
https://git.kernel.org/stable/c/7d658da725ea81c91f73087547b97e7ced82d62b
https://git.kernel.org/stable/c/709eb41adaf78d59d4579a13a898125919b69bcc
https://git.kernel.org/stable/c/1b0dc3cbb8630f0b5cb34d848628225920a904be