CVE-2026-53047 Details
Description
In the Linux kernel, the following vulnerability has been resolved: efi/capsule-loader: fix incorrect sizeof in phys array reallocation The krealloc() call for cap_info->phys in __efi_capsule_setup_info() uses sizeof(phys_addr_t *) instead of sizeof(phys_addr_t), which might be causing an undersized allocation. The allocation is also inconsistent with the initial array allocation in efi_capsule_open() that allocates one entry with sizeof(phys_addr_t), and the efi_capsule_write() function that stores phys_addr_t values (not pointers) via page_to_phys(). On 64-bit systems where sizeof(phys_addr_t) == sizeof(phys_addr_t *), this goes unnoticed. On 32-bit systems with PAE where phys_addr_t is 64-bit but pointers are 32-bit, this allocates half the required space, which might lead to a heap buffer overflow when storing physical addresses. This is similar to the bug fixed in commit fccfa646ef36 ("efi/capsule-loader: fix incorrect allocation size") which fixed the same issue at the initial allocation site.
A heap buffer overflow vulnerability has been identified in the Linux kernel's EFI capsule loader. The issue arises because the krealloc() function incorrectly uses sizeof(phys_addr_t *) instead of sizeof(phys_addr_t) when reallocating the physical address array. This miscalculation leads to an undersized allocation, particularly on 32-bit systems with PAE, where it allocates half the required space. As a result, there is a potential for a heap buffer overflow when storing physical addresses. The vulnerability has been addressed by correcting the allocation size in the capsule loader.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/22022cd8851703a58f67615a17bc7e9e8682785b | kernel.org | Patch |
| https://git.kernel.org/stable/c/48a428215782321b56956974f23593e40ce84b7a | kernel.org | Patch |
| https://git.kernel.org/stable/c/5e185330d902b12fe8e6eb4b8514b5d736d8d66d | kernel.org | Patch |
| https://git.kernel.org/stable/c/608e1f7bc9d171ab26c1fba288c97fc76363c27d | kernel.org | Patch |
| https://git.kernel.org/stable/c/67adde6bfdfd563a54b045d59aeb9a2d90c80697 | kernel.org | Patch |
| https://git.kernel.org/stable/c/8be69e9245f805566bac68ffc8574b64735fd996 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ab3f7098a3a27175b91cfc947950f5c26855801b | kernel.org | Patch |
| https://git.kernel.org/stable/c/e0e6b14995fd6fa2c0df8c712d76ab32f0694c31 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.14.13, < 4.15 >= 4.15.1, < 5.10.258 >= 5.11, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.141 >= 6.7, < 6.12.91 >= 6.13, < 6.18.33 >= 6.19, < 7.0.10 4.15 - 4.15 rc7 4.15 rc8 4.15 rc9 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | Initial Analysis | [email protected] |
| Jun 24, 2026 | New CVE Received | kernel.org |