MEDIUM

CVE-2026-53047

Linux Linux Kernel 2026-06-24 CVSS v3.1
CVSS
5.5

Description

In the Linux kernel, the following vulnerability has been resolved:

efi/capsule-loader: fix incorrect sizeof in phys array reallocation

The krealloc() call for cap_info->phys in __efi_capsule_setup_info() uses
sizeof(phys_addr_t *) instead of sizeof(phys_addr_t), which might be
causing an undersized allocation.

The allocation is also inconsistent with the initial array allocation in
efi_capsule_open() that allocates one entry with sizeof(phys_addr_t),
and the efi_capsule_write() function that stores phys_addr_t values (not
pointers) via page_to_phys().

On 64-bit systems where sizeof(phys_addr_t) == sizeof(phys_addr_t *), this
goes unnoticed. On 32-bit systems with PAE where phys_addr_t is 64-bit but
pointers are 32-bit, this allocates half the required space, which might
lead to a heap buffer overflow when storing physical addresses.

This is similar to the bug fixed in commit fccfa646ef36 ("efi/capsule-loader:
fix incorrect allocation size") which fixed the same issue at the initial
allocation site.

Summary dbcve.org

In the Linux kernel's EFI capsule-loader, a krealloc() call in __efi_capsule_setup_info() incorrectly uses sizeof(phys_addr_t *) instead of sizeof(phys_addr_t) when reallocating the phys array. On 64-bit systems this goes unnoticed as the sizes match, but on 32-bit PAE systems where phys_addr_t is 64-bit but pointers are 32-bit, this allocates half the required space, potentially causing a heap buffer overflow when storing physical addresses.

Mitigation

This is a kernel source code bug requiring a one-line fix: change sizeof(phys_addr_t *) to sizeof(phys_addr_t) in the krealloc call. No workarounds exist; systems running affected 32-bit kernels with PAE should prioritize patching.

Patch Commit

EPSS Score

0.14%
Probability of exploitation in next 30 days
3.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE