Impact
The Linux kernel’s coreboot driver performs incorrect bounds checking when parsing the firmware‑supplied table. The coreboot_table_probe routine uses size values from the table before the table is mapped, allowing a malicious firmware image to supply a 32‑bit size that overflows or advertises an extent larger than the actual resource. This causes the driver to map and parse memory beyond the intended resource, leading to memory corruption, information disclosure, and the possibility of executing arbitrary code with kernel privileges during the early boot process.
Affected Systems
All Linux kernel builds that include the coreboot driver without the upstream bounds‑check patch are affected. Any system that loads a coreboot firmware image—whether mounted on hardware with a coreboot BIOS or built into the kernel—could be compromised. The vulnerability is present in the kernel source as of the latest stable release and is not limited to a specific Linux distribution or kernel version; however, version information is not specified in the advisory.
Risk and Exploitability
The CVSS score of 7.7 reflects a high‑severity flaw capable of kernel‑level exploitation. The EPSS score of less than 1 % indicates that, to date, known exploitation attempts are rare, and the vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires delivery of a malformed coreboot firmware image, which typically occurs through a compromised vendor supply chain or physical maintenance access. Once parsed, the improper bounds checking allows the driver to access arbitrary memory, potentially leading to severe privilege escalation or system compromise during boot.
OpenCVE Enrichment
Debian DLA
Debian DSA