CVE-2026-80571

Summary

In the Linux kernel, the following vulnerability has been resolved:

powerpc/pseries: papr-phy-attest - validate cmd.length, plug mem leak

In papr_phy_attest_create_handle(), the params->cmd.length is not validated before use, which can result in a buffer overlow. Check it and return -EINVAL if it is either 0 or exceeds sizeof(params->cmd).

Also, params is freed on the success path but not error. Free it on errors after memory allocation. And free it on negative fd.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux86900ab620a42396a749b506d4a187820fc3fabe < 828a8d1a9107aec6353d896882df8383accf7e80affected
LinuxLinux86900ab620a42396a749b506d4a187820fc3fabe < ed98ce338f9a65c90cb930b088f1eb36de7181afaffected
LinuxLinux86900ab620a42396a749b506d4a187820fc3fabe < 5b17f3f34391372faf03e79d947e0c50ab6dd258affected
LinuxLinux6.16affected
LinuxLinux0 < 6.16unaffected
LinuxLinux6.18.46 <= 6.18.*unaffected
LinuxLinux7.1.10 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References