{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90341","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.804Z","datePublished":"2026-09-17T16:08:52.307Z","dateUpdated":"2026-09-18T17:54:43.963Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:54:43.963Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: coreboot: Validate table bounds\n\nThe existing coreboot_table_populate() bounds checks limit individual\nentries to the mapped length.  However, coreboot_table_probe() replaces\nthe platform resource length with header and table sizes supplied by\nfirmware before mapping the full table.\n\nA malformed table can overflow the 32-bit size addition or advertise an\nextent beyond the resource, causing the driver to map and parse memory\noutside the resource.  A resource shorter than the fixed header is also\nmapped as though it contained a complete header.\n\nReject resources shorter than the fixed header.  After validating the\nsignature, require a complete header, calculate the advertised extent\nwith overflow checking, and reject extents beyond the resource before\nremapping the table."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","baseScore":7.7,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The triggering fields are header->header_bytes and header->table_bytes in the LBIO table, read by coreboot_table_probe() after platform_get_resource(pdev, IORESOURCE_MEM, 0) from ACPI GOOGCB00/BOOT0000 _CRS or the OF /firmware/coreboot reg; those bytes come from firmware, not a network protocol message.\nAC:L - coreboot_table_probe() replaces resource_size(res) with the u32 sum header_bytes+table_bytes before memremap() and coreboot_table_populate(); firmware that sets that sum past the ACPI/DT window, or a resource shorter than sizeof(*header), hits the over-map on every bind with no race.\nPR:N - coreboot_table_probe() is the coreboot_table platform_driver probe from subsys_initcall, with no capable() or credential check; a malformed LBIO header at the GOOGCB00/coreboot MEM resource is parsed automatically, so no Linux account or user-namespace capability is required.\nUI:N - Binding the GOOGCB00/BOOT0000 or compatible=\"coreboot\" platform device calls coreboot_table_probe() during boot or module load; the oversized memremap() happens on that probe with no mount, open, or other victim action.\nS:U - The oversized memremap() in coreboot_table_probe() and the memcpy() in coreboot_table_populate() stay in this kernel's coreboot table parser; this is not a KVM/Xen guest-to-host, IOMMU, or sandbox boundary crossing.\nC:H - memremap(res->start, header_bytes+table_bytes) then coreboot_table_populate() memcpy's each entry->size from that mapping into a kmalloc'd coreboot_device; table_bytes is an unconstrained u32, so this is an unbounded over-read of physical memory past the ACPI/DT resource, not a few-byte leak.\nI:N - coreboot_table_populate() copies into kzalloc(sizeof(device->dev)+entry->size) using the same entry->size already checked against the (oversize) mapping, so the destination matches the copy; this path has no out-of-bounds write or control-flow hijack primitive.\nA:H - try_ram_remap() in memremap() returns __va(res->start) after checking only the first pfn, so populate's walk of a table_bytes that extends past the reserved coreboot table/CBMEM window can fault on a linear-map hole or mixed RAM/MMIO range and oops or panic."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/firmware/google/coreboot_table.c"],"versions":[{"version":"d384d6f43d1ec3f1225ab0275fd592c5980bd830","lessThan":"3cca0d6dd4c2636d2514234233cb02db76621607","status":"affected","versionType":"git"},{"version":"d384d6f43d1ec3f1225ab0275fd592c5980bd830","lessThan":"f79f621215a0944c4a0e1b3b86b99e433ae8c527","status":"affected","versionType":"git"},{"version":"d384d6f43d1ec3f1225ab0275fd592c5980bd830","lessThan":"d848fac90c6f0566e7b93066b0b86024f65f395e","status":"affected","versionType":"git"},{"version":"d384d6f43d1ec3f1225ab0275fd592c5980bd830","lessThan":"88027241c1d2c3213bac937a1c2cb89a5775a413","status":"affected","versionType":"git"},{"version":"d384d6f43d1ec3f1225ab0275fd592c5980bd830","lessThan":"fd93859ecfa5b6495a6863c18fd923a7666def26","status":"affected","versionType":"git"},{"version":"d384d6f43d1ec3f1225ab0275fd592c5980bd830","lessThan":"2d98a3b89394f283f054a4a54587c14ee89acaf9","status":"affected","versionType":"git"},{"version":"d384d6f43d1ec3f1225ab0275fd592c5980bd830","lessThan":"e82f260a74dea8cdd7857f2cc66f73d0da522bb3","status":"affected","versionType":"git"},{"version":"d384d6f43d1ec3f1225ab0275fd592c5980bd830","lessThan":"a58a57a1076f8c5dae0327e3710899478c3be901","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/firmware/google/coreboot_table.c"],"versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/3cca0d6dd4c2636d2514234233cb02db76621607"},{"url":"https://git.kernel.org/stable/c/f79f621215a0944c4a0e1b3b86b99e433ae8c527"},{"url":"https://git.kernel.org/stable/c/d848fac90c6f0566e7b93066b0b86024f65f395e"},{"url":"https://git.kernel.org/stable/c/88027241c1d2c3213bac937a1c2cb89a5775a413"},{"url":"https://git.kernel.org/stable/c/fd93859ecfa5b6495a6863c18fd923a7666def26"},{"url":"https://git.kernel.org/stable/c/2d98a3b89394f283f054a4a54587c14ee89acaf9"},{"url":"https://git.kernel.org/stable/c/e82f260a74dea8cdd7857f2cc66f73d0da522bb3"},{"url":"https://git.kernel.org/stable/c/a58a57a1076f8c5dae0327e3710899478c3be901"}],"title":"firmware: coreboot: Validate table bounds","x_generator":{"engine":"bippy-1.2.0"}}}}