PT-2026-37617 · Linux+2 · Linux Kernel+2
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the APEI/GHES component where the
ghes new() function fails to properly validate the size of CPER records. While the logic prevents allocating records larger than GHES ESTATUS MAX SIZE (64KB), the actual allocation is based on the number of pages from the CPER bios table location, which may be smaller. Consequently, malicious firmware could send data exceeding the allocated memory, leading to a kernel OOPS (a type of kernel panic or crash).Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu