CVE-2026-53047
Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
24/06/2026
Última modificación:
21/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
efi/capsule-loader: fix incorrect sizeof in phys array reallocation<br />
<br />
The krealloc() call for cap_info->phys in __efi_capsule_setup_info() uses<br />
sizeof(phys_addr_t *) instead of sizeof(phys_addr_t), which might be<br />
causing an undersized allocation.<br />
<br />
The allocation is also inconsistent with the initial array allocation in<br />
efi_capsule_open() that allocates one entry with sizeof(phys_addr_t),<br />
and the efi_capsule_write() function that stores phys_addr_t values (not<br />
pointers) via page_to_phys().<br />
<br />
On 64-bit systems where sizeof(phys_addr_t) == sizeof(phys_addr_t *), this<br />
goes unnoticed. On 32-bit systems with PAE where phys_addr_t is 64-bit but<br />
pointers are 32-bit, this allocates half the required space, which might<br />
lead to a heap buffer overflow when storing physical addresses.<br />
<br />
This is similar to the bug fixed in commit fccfa646ef36 ("efi/capsule-loader:<br />
fix incorrect allocation size") which fixed the same issue at the initial<br />
allocation site.
Impacto
Puntuación base 3.x
5.50
Gravedad 3.x
MEDIA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.14.13 (incluyendo) | 4.15 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.15.1 (incluyendo) | 5.10.258 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (incluyendo) | 5.15.209 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (incluyendo) | 6.1.175 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (incluyendo) | 6.6.141 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (incluyendo) | 6.12.91 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (incluyendo) | 6.18.33 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (incluyendo) | 7.0.10 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:4.15:-:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.15:rc7:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.15:rc8:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.15:rc9:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/22022cd8851703a58f67615a17bc7e9e8682785b
- https://git.kernel.org/stable/c/48a428215782321b56956974f23593e40ce84b7a
- https://git.kernel.org/stable/c/5e185330d902b12fe8e6eb4b8514b5d736d8d66d
- https://git.kernel.org/stable/c/608e1f7bc9d171ab26c1fba288c97fc76363c27d
- https://git.kernel.org/stable/c/67adde6bfdfd563a54b045d59aeb9a2d90c80697
- https://git.kernel.org/stable/c/8be69e9245f805566bac68ffc8574b64735fd996
- https://git.kernel.org/stable/c/ab3f7098a3a27175b91cfc947950f5c26855801b
- https://git.kernel.org/stable/c/e0e6b14995fd6fa2c0df8c712d76ab32f0694c31



