Description
In the Linux kernel, the following vulnerability has been resolved:

ACPI: pfr_update: fix stack buffer overflow in query_capability()

query_capability() copies four ACPI buffer objects returned by the
firmware _DSM into fixed-size u8[16] fields in struct
pfru_update_cap_info using memcpy with the firmware-supplied length:

memcpy(&cap_hdr->code_type,
elements[CAP_CODE_TYPE_IDX].buffer.pointer,
elements[CAP_CODE_TYPE_IDX].buffer.length);

The same pattern repeats for drv_type, platform_id, and oem_id.
If the firmware returns buffer.length > 16 for any of these fields,
memcpy writes past the destination array.

struct pfru_update_cap_info is stack-allocated in pfru_ioctl().

Confirmed with KASAN on 7.2-rc6: three stack-out-of-bounds reports
are generated when a DSM returns 64-byte buffers, with writes reaching
44 bytes past the end of cap_hdr's [64, 156) frame window into
adjacent stack redzones.

Introduce a helper pointer to out_obj->package.elements and use it
to validate each buffer length against its destination field size
before copying, returning -EINVAL if the firmware supplies an
oversized buffer.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption due to stack buffer overflow
Action: Apply patch
AI Analysis

Impact

An overflow in the ACPI pfr_update subsystem occurs when the kernel copies‑supplied buffer into stack memory without validating the buffer length. If the firmware returns a longer buffer, the memcpy writes beyond the array boundary in kernel memory corruption that can crash the system or allow further exploitation. The flaw is a classic stack buffer overflow (CWE-120).

Affected Systems

The vulnerability affects Linux kernel implementations that have not‑validation commit. All dist query as indicated by the product name Linux and the kernel CPE entry. No specific product version range is supplied in the data, so the only indicator is that the fix has been applied in newer kernels.

Risk and Exploitability

The CVSS score of 7.8 classifies the flaw as high severity. The EPSS score of <1% suggests a very low probability of exploitation, and it does not appear in the CISA KEV catalog. The flaw requires that an attacker supply an oversized ACPI buffer via a _DSM entry, which typically means having control over the system firmware or access to physical hardware to inject a custom ACPI table. Based on the description, this is inferred as the likely attack vector.

Generated by OpenCVE AI on September 15, 2026 at 21:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Switch to a Linux kernel version that includes the ACPI pfr_update length‑validation patch.
  • If an upgrade is not immediately possible, block or remove the pfr_update _DSM entry from the ACPI tables to prevent firmware from triggering the vulnerable code, for example by editing firmware tables or using tools that strip _DSM entries.
  • Ensure that the system firmware is current and signed, so that only trusted ACPI tables are loaded; in environments with custom firmware updates that do not use oversized buffers.

Generated by OpenCVE AI on September 15, 2026 at 21:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ACPI: pfr_update: fix stack buffer overflow in query_capability() query_capability() copies four ACPI buffer objects returned by the firmware _DSM into fixed-size u8[16] fields in struct pfru_update_cap_info using memcpy with the firmware-supplied length: memcpy(&cap_hdr->code_type, elements[CAP_CODE_TYPE_IDX].buffer.pointer, elements[CAP_CODE_TYPE_IDX].buffer.length); The same pattern repeats for drv_type, platform_id, and oem_id. If the firmware returns buffer.length > 16 for any of these fields, memcpy writes past the destination array. struct pfru_update_cap_info is stack-allocated in pfru_ioctl(). Confirmed with KASAN on 7.2-rc6: three stack-out-of-bounds reports are generated when a DSM returns 64-byte buffers, with writes reaching 44 bytes past the end of cap_hdr's [64, 156) frame window into adjacent stack redzones. Introduce a helper pointer to out_obj->package.elements and use it to validate each buffer length against its destination field size before copying, returning -EINVAL if the firmware supplies an oversized buffer.
Title ACPI: pfr_update: fix stack buffer overflow in query_capability()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:01:14.959Z

Reserved: 2026-09-11T19:38:34.729Z

Link: CVE-2026-89587

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:43.170

Modified: 2026-09-14T13:19:13.060

Link: CVE-2026-89587

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:52Z

Links: CVE-2026-89587 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:45:17Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')