7.7

CVE-2026-90341

firmware: coreboot: Validate table bounds

In the Linux kernel, the following vulnerability has been resolved:

firmware: coreboot: Validate table bounds

The existing coreboot_table_populate() bounds checks limit individual
entries to the mapped length.  However, coreboot_table_probe() replaces
the platform resource length with header and table sizes supplied by
firmware before mapping the full table.

A malformed table can overflow the 32-bit size addition or advertise an
extent beyond the resource, causing the driver to map and parse memory
outside the resource.  A resource shorter than the fixed header is also
mapped as though it contained a complete header.

Reject resources shorter than the fixed header.  After validating the
signature, require a complete header, calculate the advertised extent
with overflow checking, and reject extents beyond the resource before
remapping the table.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version d384d6f43d1ec3f1225ab0275fd592c5980bd830
Version < 3cca0d6dd4c2636d2514234233cb02db76621607
Status affected
Version d384d6f43d1ec3f1225ab0275fd592c5980bd830
Version < f79f621215a0944c4a0e1b3b86b99e433ae8c527
Status affected
Version d384d6f43d1ec3f1225ab0275fd592c5980bd830
Version < d848fac90c6f0566e7b93066b0b86024f65f395e
Status affected
Version d384d6f43d1ec3f1225ab0275fd592c5980bd830
Version < 88027241c1d2c3213bac937a1c2cb89a5775a413
Status affected
Version d384d6f43d1ec3f1225ab0275fd592c5980bd830
Version < fd93859ecfa5b6495a6863c18fd923a7666def26
Status affected
Version d384d6f43d1ec3f1225ab0275fd592c5980bd830
Version < 2d98a3b89394f283f054a4a54587c14ee89acaf9
Status affected
Version d384d6f43d1ec3f1225ab0275fd592c5980bd830
Version < e82f260a74dea8cdd7857f2cc66f73d0da522bb3
Status affected
Version d384d6f43d1ec3f1225ab0275fd592c5980bd830
Version < a58a57a1076f8c5dae0327e3710899478c3be901
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.12
Status affected
Version 0
Version < 4.12
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.079
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.7 2.5 5.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/3cca0d6dd4c2636d2514234233cb02db76621607
https://git.kernel.org/stable/c/f79f621215a0944c4a0e1b3b86b99e433ae8c527
https://git.kernel.org/stable/c/d848fac90c6f0566e7b93066b0b86024f65f395e
https://git.kernel.org/stable/c/88027241c1d2c3213bac937a1c2cb89a5775a413
https://git.kernel.org/stable/c/fd93859ecfa5b6495a6863c18fd923a7666def26
https://git.kernel.org/stable/c/2d98a3b89394f283f054a4a54587c14ee89acaf9
https://git.kernel.org/stable/c/e82f260a74dea8cdd7857f2cc66f73d0da522bb3
https://git.kernel.org/stable/c/a58a57a1076f8c5dae0327e3710899478c3be901