Buffer Overflow Vulnerability in Linux Kernel Affecting PowerPC/Pseries
CVE-2026-80571
What is CVE-2026-80571?
A vulnerability exists in the Linux kernel specifically within the PowerPC/Pseries architecture, related to the papr_phy_attest_create_handle function. The 'cmd.length' parameter is inadequately validated, leading to potential buffer overflow scenarios. Additionally, there are issues related to memory management as memory allocated on successful execution is not properly freed when errors occur, which can lead to memory leaks. The vulnerability necessitates validation checks to ensure the command length is a valid value that does not exceed expected limits, alongside proper cleanup on error conditions.
Affected Version(s)
Linux 86900ab620a42396a749b506d4a187820fc3fabe < 828a8d1a9107aec6353d896882df8383accf7e80
Linux 86900ab620a42396a749b506d4a187820fc3fabe
Linux 86900ab620a42396a749b506d4a187820fc3fabe < 5b17f3f34391372faf03e79d947e0c50ab6dd258