Heap-based buffer overflow in Linux kernel - CVE-2026-53047
Published: June 25, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in the efi capsule loader when reallocating the phys array. A local user can trigger the vulnerable code path to cause a denial of service.
The issue affects 32-bit systems with PAE where phys_addr_t is 64-bit but pointers are 32-bit.
How to mitigate CVE-2026-53047
Sources
- https://git.kernel.org/stable/c/22022cd8851703a58f67615a17bc7e9e8682785b
- https://git.kernel.org/stable/c/48a428215782321b56956974f23593e40ce84b7a
- https://git.kernel.org/stable/c/5e185330d902b12fe8e6eb4b8514b5d736d8d66d
- https://git.kernel.org/stable/c/608e1f7bc9d171ab26c1fba288c97fc76363c27d
- https://git.kernel.org/stable/c/67adde6bfdfd563a54b045d59aeb9a2d90c80697
- https://git.kernel.org/stable/c/8be69e9245f805566bac68ffc8574b64735fd996
- https://git.kernel.org/stable/c/ab3f7098a3a27175b91cfc947950f5c26855801b
- https://git.kernel.org/stable/c/e0e6b14995fd6fa2c0df8c712d76ab32f0694c31