In the Linux kernel, the following vulnerability has been resolved: efi/capsule-loader: fix incorrect sizeof in phys array reallocation The krealloc() call for cap_info->phys in __efi_capsule_setup…
中危 CVSS 5.5
摘要
In the Linux kernel, the following vulnerability has been resolved: efi/capsule-loader: fix incorrect sizeof in phys array reallocation The krealloc() call for cap_info->phys in __efi_capsule_setup_info() uses sizeof(phys_addr_t *) instead of sizeof(phys_addr_t), which might be causing an undersized allocation. The allocation is also inconsistent with the initial array allocation in efi_capsule_open() that allocates one entry with sizeof(phys_addr_t), and the efi_capsule_write() function tha…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://git.kernel.org/stable/c/22022cd8851703a58f67615a17bc7e9e8682785b Patch
- https://git.kernel.org/stable/c/48a428215782321b56956974f23593e40ce84b7a Patch
- https://git.kernel.org/stable/c/5e185330d902b12fe8e6eb4b8514b5d736d8d66d Patch
- https://git.kernel.org/stable/c/608e1f7bc9d171ab26c1fba288c97fc76363c27d Patch
- https://git.kernel.org/stable/c/67adde6bfdfd563a54b045d59aeb9a2d90c80697 Patch
- https://git.kernel.org/stable/c/8be69e9245f805566bac68ffc8574b64735fd996 Patch
- https://git.kernel.org/stable/c/ab3f7098a3a27175b91cfc947950f5c26855801b Patch
- https://git.kernel.org/stable/c/e0e6b14995fd6fa2c0df8c712d76ab32f0694c31 Patch
时间线
- nvd_ingest NVD