« Volver al listado

CVE-2026-53047

Estado: AnalizadaMedia (5.5)—

In the Linux kernel, the following vulnerability has been resolved:

efi/capsule-loader: fix incorrect sizeof in phys array reallocation

The krealloc() call for cap_info->phys in __efi_capsule_setup_info() uses sizeof(phys_addr_t *) instead of sizeof(phys_addr_t), which might be causing an undersized allocation.

The allocation is also inconsistent with the initial array allocation in efi_capsule_open() that allocates one entry with sizeof(phys_addr_t), and the efi_capsule_write() function that stores phys_addr_t values (not pointers) via page_to_phys().

On 64-bit systems where sizeof(phys_addr_t) == sizeof(phys_addr_t *), this goes unnoticed.

Leer descripción completaMostrar menos

On 32-bit systems with PAE where phys_addr_t is 64-bit but pointers are 32-bit, this allocates half the required space, which might lead to a heap buffer overflow when storing physical addresses.

This is similar to the bug fixed in commit fccfa646ef36 ("efi/capsule-loader: fix incorrect allocation size") which fixed the same issue at the initial allocation site.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-53047",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "f24c4d478013d82bd1b943df566fff3561d52864",
              "lessThan": "22022cd8851703a58f67615a17bc7e9e8682785b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f24c4d478013d82bd1b943df566fff3561d52864",
              "lessThan": "67adde6bfdfd563a54b045d59aeb9a2d90c80697",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f24c4d478013d82bd1b943df566fff3561d52864",
              "lessThan": "608e1f7bc9d171ab26c1fba288c97fc76363c27d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f24c4d478013d82bd1b943df566fff3561d52864",
              "lessThan": "8be69e9245f805566bac68ffc8574b64735fd996",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f24c4d478013d82bd1b943df566fff3561d52864",
              "lessThan": "5e185330d902b12fe8e6eb4b8514b5d736d8d66d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f24c4d478013d82bd1b943df566fff3561d52864",
              "lessThan": "e0e6b14995fd6fa2c0df8c712d76ab32f0694c31",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f24c4d478013d82bd1b943df566fff3561d52864",
              "lessThan": "ab3f7098a3a27175b91cfc947950f5c26855801b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f24c4d478013d82bd1b943df566fff3561d52864",
              "lessThan": "48a428215782321b56956974f23593e40ce84b7a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "95a362c9a6892085f714eb6e31eea6a0e3aa93bf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4.14.13",
              "lessThan": "4.15",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/firmware/efi/capsule-loader.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.258",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.209",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.175",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.141",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.91",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.33",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.0.10",
              "versionType": "semver",
              "lessThanOrEqual": "7.0.*"
            },
            {
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/firmware/efi/capsule-loader.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-06-24T17:17:16.533",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/22022cd8851703a58f67615a17bc7e9e8682785b",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/48a428215782321b56956974f23593e40ce84b7a",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5e185330d902b12fe8e6eb4b8514b5d736d8d66d",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/608e1f7bc9d171ab26c1fba288c97fc76363c27d",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/67adde6bfdfd563a54b045d59aeb9a2d90c80697",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8be69e9245f805566bac68ffc8574b64735fd996",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ab3f7098a3a27175b91cfc947950f5c26855801b",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e0e6b14995fd6fa2c0df8c712d76ab32f0694c31",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nefi/capsule-loader: fix incorrect sizeof in phys array reallocation\n\nThe krealloc() call for cap_info->phys in __efi_capsule_setup_info() uses\nsizeof(phys_addr_t *) instead of sizeof(phys_addr_t), which might be\ncausing an undersized allocation.\n\nThe allocation is also inconsistent with the initial array allocation in\nefi_capsule_open() that allocates one entry with sizeof(phys_addr_t),\nand the efi_capsule_write() function that stores phys_addr_t values (not\npointers) via page_to_phys().\n\nOn 64-bit systems where sizeof(phys_addr_t) == sizeof(phys_addr_t *), this\ngoes unnoticed. On 32-bit systems with PAE where phys_addr_t is 64-bit but\npointers are 32-bit, this allocates half the required space, which might\nlead to a heap buffer overflow when storing physical addresses.\n\nThis is similar to the bug fixed in commit fccfa646ef36 (\"efi/capsule-loader:\nfix incorrect allocation size\") which fixed the same issue at the initial\nallocation site."
    }
  ],
  "lastModified": "2026-07-21T17:22:44.967",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4B245EE2-CC73-420B-B573-93C5323D9433",
              "versionEndExcluding": "4.15",
              "versionStartIncluding": "4.14.13"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "025D79B4-921A-41A7-A695-91D339C3ABF1",
              "versionEndExcluding": "5.10.258",
              "versionStartIncluding": "4.15.1"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "919C10A9-7951-4A74-BADD-C135A0A8D8B4",
              "versionEndExcluding": "5.15.209",
              "versionStartIncluding": "5.11"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "92385813-D91D-480D-83A1-F423D2CBB2BA",
              "versionEndExcluding": "6.1.175",
              "versionStartIncluding": "5.16"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "97A9FFFA-22BB-4D5C-9790-5A2286E392F7",
              "versionEndExcluding": "6.6.141",
              "versionStartIncluding": "6.2"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C918746B-DE6F-448F-A93E-A04C5481688D",
              "versionEndExcluding": "6.12.91",
              "versionStartIncluding": "6.7"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "96D99E49-380D-43AB-BDBA-25C3AD018A9C",
              "versionEndExcluding": "6.18.33",
              "versionStartIncluding": "6.13"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A13475D2-59BF-4716-94B5-7C1D239A2CF4",
              "versionEndExcluding": "7.0.10",
              "versionStartIncluding": "6.19"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:4.15:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B4D39AF-668B-442B-8085-639A6D4FA5AC"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:4.15:rc7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A282AD0B-2D63-4F05-8F89-109A0975B423"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:4.15:rc8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "30358221-183C-4699-994E-AF51F5D534FC"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:4.15:rc9:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A5ED80A8-E656-4AE9-921B-C22402C94A4C"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}