Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-53047

Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
24/06/2026
Última modificación:
21/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> efi/capsule-loader: fix incorrect sizeof in phys array reallocation<br /> <br /> The krealloc() call for cap_info-&gt;phys in __efi_capsule_setup_info() uses<br /> sizeof(phys_addr_t *) instead of sizeof(phys_addr_t), which might be<br /> causing an undersized allocation.<br /> <br /> The allocation is also inconsistent with the initial array allocation in<br /> efi_capsule_open() that allocates one entry with sizeof(phys_addr_t),<br /> and the efi_capsule_write() function that stores phys_addr_t values (not<br /> pointers) via page_to_phys().<br /> <br /> On 64-bit systems where sizeof(phys_addr_t) == sizeof(phys_addr_t *), this<br /> goes unnoticed. On 32-bit systems with PAE where phys_addr_t is 64-bit but<br /> pointers are 32-bit, this allocates half the required space, which might<br /> lead to a heap buffer overflow when storing physical addresses.<br /> <br /> This is similar to the bug fixed in commit fccfa646ef36 ("efi/capsule-loader:<br /> fix incorrect allocation size") which fixed the same issue at the initial<br /> allocation site.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.14.13 (incluyendo) 4.15 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.15.1 (incluyendo) 5.10.258 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (incluyendo) 5.15.209 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (incluyendo) 6.1.175 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (incluyendo) 6.6.141 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (incluyendo) 6.12.91 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (incluyendo) 6.18.33 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (incluyendo) 7.0.10 (excluyendo)
cpe:2.3:o:linux:linux_kernel:4.15:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:4.15:rc7:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:4.15:rc8:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:4.15:rc9:*:*:*:*:*:*