Executive brief
A vulnerability was identified in the Linux kernel's efivarfs file system, which is used to access EFI variables. An attacker with local access could trigger a system crash or potentially access restricted memory by using specially crafted, invalid filenames during file lookups. This could lead to a denial of service or unauthorized information disclosure, impacting the stability and security of the affected system.
Technical details
A slab-out-of-bounds read vulnerability exists in the efivarfs_d_compare function within the Linux kernel's efivarfs file system. The root cause is a missing length check: if a dentry name length is less than EFI_VARIABLE_GUID_LEN, the calculated 'guid' offset becomes negative, leading to an out-of-bounds memory access during a memcmp operation. This race condition can be triggered by parallel lookups where an invalid dentry is temporarily added to the hash list and subsequently retrieved by a concurrent process. An attacker with local privileges can exploit this to cause a kernel panic (DoS) or read sensitive kernel memory. The issue has been patched in multiple stable kernel branches by adding a check to ensure the filename length is sufficient before performing the comparison.
Affected products
- Linux Linux Kernel 6.6, 6.1, 5.15, 5.10, 5.4, 4.19, 4.14, 4.9
- Siemens SIMATIC CN 4100 < V5.0
Timeline
- 2025-08-27: patched: Initial patch authored
- 2025-09-16: disclosed: CVE published
References
- https://git.kernel.org/stable/c/0f63fbabeaaaaaaf5b742a2f4c1b4590d50bf1f6
- https://git.kernel.org/stable/c/568e7761279b99c6daa3002290fd6d8047ddb6d2
- https://git.kernel.org/stable/c/71581a82f38e5a4d807d71fc1bb59aead80ccf95
- https://git.kernel.org/stable/c/794399019301944fd6d2e0d7a51b3327e26c410e
- https://git.kernel.org/stable/c/925599eba46045930b850a98ae594d2e3028ac40
- https://git.kernel.org/stable/c/a6358f8cf64850f3f27857b8ed8c1b08cfc4685c
- https://git.kernel.org/stable/c/c2925cd6207079c3f4d040d082515db78d63afbf