Description
In the Linux kernel, the following vulnerability has been resolved:

firmware: coreboot: Validate table bounds

The existing coreboot_table_populate() bounds checks limit individual
entries to the mapped length. However, coreboot_table_probe() replaces
the platform resource length with header and table sizes supplied by
firmware before mapping the full table.

A malformed table can overflow the 32-bit size addition or advertise an
extent beyond the resource, causing the driver to map and parse memory
outside the resource. A resource shorter than the fixed header is also
mapped as though it contained a complete header.

Reject resources shorter than the fixed header. After validating the
signature, require a complete header, calculate the advertised extent
with overflow checking, and reject extents beyond the resource before
remapping the table.
Published: 2026-09-17
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary Code Execution
Action: Patch
AI Analysis

Impact

The Linux kernel’s coreboot driver performs incorrect bounds checking when parsing the firmware‑supplied table. The coreboot_table_probe routine uses size values from the table before the table is mapped, allowing a malicious firmware image to supply a 32‑bit size that overflows or advertises an extent larger than the actual resource. This causes the driver to map and parse memory beyond the intended resource, leading to memory corruption, information disclosure, and the possibility of executing arbitrary code with kernel privileges during the early boot process.

Affected Systems

All Linux kernel builds that include the coreboot driver without the upstream bounds‑check patch are affected. Any system that loads a coreboot firmware image—whether mounted on hardware with a coreboot BIOS or built into the kernel—could be compromised. The vulnerability is present in the kernel source as of the latest stable release and is not limited to a specific Linux distribution or kernel version; however, version information is not specified in the advisory.

Risk and Exploitability

The CVSS score of 7.7 reflects a high‑severity flaw capable of kernel‑level exploitation. The EPSS score of less than 1 % indicates that, to date, known exploitation attempts are rare, and the vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires delivery of a malformed coreboot firmware image, which typically occurs through a compromised vendor supply chain or physical maintenance access. Once parsed, the improper bounds checking allows the driver to access arbitrary memory, potentially leading to severe privilege escalation or system compromise during boot.

Generated by OpenCVE AI on September 19, 2026 at 15:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that includes the coreboot bounds‑checking patch
  • If an update is not yet available, compile the kernel without coreboot support or remove the coreboot driver from the configuration
  • Ensure that any coreboot firmware image loaded at boot is authenticated and signed to detect tampering before it is parsed by the driver

Generated by OpenCVE AI on September 19, 2026 at 15:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-20

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: firmware: coreboot: Validate table bounds The existing coreboot_table_populate() bounds checks limit individual entries to the mapped length. However, coreboot_table_probe() replaces the platform resource length with header and table sizes supplied by firmware before mapping the full table. A malformed table can overflow the 32-bit size addition or advertise an extent beyond the resource, causing the driver to map and parse memory outside the resource. A resource shorter than the fixed header is also mapped as though it contained a complete header. Reject resources shorter than the fixed header. After validating the signature, require a complete header, calculate the advertised extent with overflow checking, and reject extents beyond the resource before remapping the table.
Title firmware: coreboot: Validate table bounds
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:43.963Z

Reserved: 2026-09-11T19:38:34.804Z

Link: CVE-2026-90341

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:32.740

Modified: 2026-09-18T18:17:54.583

Link: CVE-2026-90341

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:45:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-20

    Improper Input Validation