CVE-2026-53047
Description
In the Linux kernel, the following vulnerability has been resolved:
efi/capsule-loader: fix incorrect sizeof in phys array reallocation
The krealloc() call for cap_info->phys in __efi_capsule_setup_info() uses
sizeof(phys_addr_t *) instead of sizeof(phys_addr_t), which might be
causing an undersized allocation.
The allocation is also inconsistent with the initial array allocation in
efi_capsule_open() that allocates one entry with sizeof(phys_addr_t),
and the efi_capsule_write() function that stores phys_addr_t values (not
pointers) via page_to_phys().
On 64-bit systems where sizeof(phys_addr_t) == sizeof(phys_addr_t *), this
goes unnoticed. On 32-bit systems with PAE where phys_addr_t is 64-bit but
pointers are 32-bit, this allocates half the required space, which might
lead to a heap buffer overflow when storing physical addresses.
This is similar to the bug fixed in commit fccfa646ef36 ("efi/capsule-loader:
fix incorrect allocation size") which fixed the same issue at the initial
allocation site.
Summary dbcve.org
In the Linux kernel's EFI capsule-loader, a krealloc() call in __efi_capsule_setup_info() incorrectly uses sizeof(phys_addr_t *) instead of sizeof(phys_addr_t) when reallocating the phys array. On 64-bit systems this goes unnoticed as the sizes match, but on 32-bit PAE systems where phys_addr_t is 64-bit but pointers are 32-bit, this allocates half the required space, potentially causing a heap buffer overflow when storing physical addresses.
Mitigation
This is a kernel source code bug requiring a one-line fix: change sizeof(phys_addr_t *) to sizeof(phys_addr_t) in the krealloc call. No workarounds exist; systems running affected 32-bit kernels with PAE should prioritize patching.