Description
In the Linux kernel, the following vulnerability has been resolved:

ACPI: pfr_update: fix stack buffer overflow in query_capability()

query_capability() copies four ACPI buffer objects returned by the
firmware _DSM into fixed-size u8[16] fields in struct
pfru_update_cap_info using memcpy with the firmware-supplied length:

memcpy(&cap_hdr->code_type,
elements[CAP_CODE_TYPE_IDX].buffer.pointer,
elements[CAP_CODE_TYPE_IDX].buffer.length);

The same pattern repeats for drv_type, platform_id, and oem_id.
If the firmware returns buffer.length > 16 for any of these fields,
memcpy writes past the destination array.

struct pfru_update_cap_info is stack-allocated in pfru_ioctl().

Confirmed with KASAN on 7.2-rc6: three stack-out-of-bounds reports
are generated when a DSM returns 64-byte buffers, with writes reaching
44 bytes past the end of cap_hdr's [64, 156) frame window into
adjacent stack redzones.

Introduce a helper pointer to out_obj->package.elements and use it
to validate each buffer length against its destination field size
before copying, returning -EINVAL if the firmware supplies an
oversized buffer.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption due to stack buffer overflow
Action: Update kernel
AI Analysis

Impact

This vulnerability occurs in the ACPI pfr_update subsystem of the Linux kernel. The query_capability() function copies four ACPI buffer objects, returned by firmware through the _DSM interface, into fixed-size 16‑byte fields on the kernel stack using memcpy without checking the source length. When the firmware provides a buffer longer than 16 bytes, the memcpy overruns the destination array, corrupting adjacent stack memory. The result is kernel memory corruption which can destabilize the kernel or trigger a crash. The weakness is a classic buffer overflow (CWE‑120).

Affected Systems

Any Linux kernel release that has not yet incorporated the ACPI pfr_update length‑validation commit is affected. This includes stock kernels from distributions that still run the older code. Systems that load ACPI tables containing a _DSM entry that exercises pfr_update—especially if the firmware is not properly signed or validated—are susceptible.

Risk and Exploitability

The CVSS score of 5.7 classifies this issue as a moderate severity flaw. The EPSS score is reported as <1%, indicating a very low probability of exploitation; the flaw is not listed in the CISA KEV catalog. The likely attack vector is the ability to supply or modify firmware ACPI tables, a privilege normally restricted to firmware developers or users with physical access to the hardware. Consequently, the practical risk to a typical end‑user environment remains low, although a local privileged attacker who controls the firmware could potentially trigger kernel memory corruption.

Generated by OpenCVE AI on September 13, 2026 at 06:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that contains the ACPI pfr_update length validation commit.
  • If an upgrade is not immediately possible, disable or remove the offending _DSM entry from the firmware or configure the ACPI subsystem to ignore pfr_update capability.
  • Implement firmware integrity mechanisms such as enforcing signed ACPI tables to prevent the loading of unauthorized or tampered firmware that may supply oversized buffers.

Generated by OpenCVE AI on September 13, 2026 at 06:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ACPI: pfr_update: fix stack buffer overflow in query_capability() query_capability() copies four ACPI buffer objects returned by the firmware _DSM into fixed-size u8[16] fields in struct pfru_update_cap_info using memcpy with the firmware-supplied length: memcpy(&cap_hdr->code_type, elements[CAP_CODE_TYPE_IDX].buffer.pointer, elements[CAP_CODE_TYPE_IDX].buffer.length); The same pattern repeats for drv_type, platform_id, and oem_id. If the firmware returns buffer.length > 16 for any of these fields, memcpy writes past the destination array. struct pfru_update_cap_info is stack-allocated in pfru_ioctl(). Confirmed with KASAN on 7.2-rc6: three stack-out-of-bounds reports are generated when a DSM returns 64-byte buffers, with writes reaching 44 bytes past the end of cap_hdr's [64, 156) frame window into adjacent stack redzones. Introduce a helper pointer to out_obj->package.elements and use it to validate each buffer length against its destination field size before copying, returning -EINVAL if the firmware supplies an oversized buffer.
Title ACPI: pfr_update: fix stack buffer overflow in query_capability()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:31:22.874Z

Reserved: 2026-09-11T19:38:34.729Z

Link: CVE-2026-89587

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:43.170

Modified: 2026-09-13T07:17:24.500

Link: CVE-2026-89587

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:52Z

Links: CVE-2026-89587 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T06:45:18Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')