---
id: CVE-2026-90341
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  firmware: coreboot: Validate table bounds

  The existing coreboot_table_populate() bounds checks limit individual
  entries to the mapped length
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  firmware: coreboot: Validate table bounds

  The existing coreboot_table_populate() bounds checks limit individual
  entries to the mapped length.  However, coreboot_table_…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= d384d6f43d1ec3f1225ab0275fd592c5980bd830 <
    3cca0d6dd4c2636d2514234233cb02db76621607
  - >-
    Linux >= d384d6f43d1ec3f1225ab0275fd592c5980bd830 <
    f79f621215a0944c4a0e1b3b86b99e433ae8c527
  - >-
    Linux >= d384d6f43d1ec3f1225ab0275fd592c5980bd830 <
    d848fac90c6f0566e7b93066b0b86024f65f395e
  - >-
    Linux >= d384d6f43d1ec3f1225ab0275fd592c5980bd830 <
    88027241c1d2c3213bac937a1c2cb89a5775a413
  - >-
    Linux >= d384d6f43d1ec3f1225ab0275fd592c5980bd830 <
    fd93859ecfa5b6495a6863c18fd923a7666def26
  - >-
    Linux >= d384d6f43d1ec3f1225ab0275fd592c5980bd830 <
    2d98a3b89394f283f054a4a54587c14ee89acaf9
  - >-
    Linux >= d384d6f43d1ec3f1225ab0275fd592c5980bd830 <
    e82f260a74dea8cdd7857f2cc66f73d0da522bb3
  - >-
    Linux >= d384d6f43d1ec3f1225ab0275fd592c5980bd830 <
    a58a57a1076f8c5dae0327e3710899478c3be901
  - Linux 4.12
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:17:54.583'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90341'
references:
  - url: 'https://git.kernel.org/stable/c/2d98a3b89394f283f054a4a54587c14ee89acaf9'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/3cca0d6dd4c2636d2514234233cb02db76621607'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/88027241c1d2c3213bac937a1c2cb89a5775a413'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a58a57a1076f8c5dae0327e3710899478c3be901'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d848fac90c6f0566e7b93066b0b86024f65f395e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e82f260a74dea8cdd7857f2cc66f73d0da522bb3'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f79f621215a0944c4a0e1b3b86b99e433ae8c527'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/fd93859ecfa5b6495a6863c18fd923a7666def26'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
epss: 0.0018
epssPercentile: 0.07832
ingestedAt: '2026-09-17T16:21:47.818Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

firmware: coreboot: Validate table bounds

The existing coreboot_table_populate() bounds checks limit individual
entries to the mapped length.  However, coreboot_table_probe() replaces
the platform resource length with header and table sizes supplied by
firmware before mapping the full table.

A malformed table can overflow the 32-bit size addition or advertise an
extent beyond the resource, causing the driver to map and parse memory
outside the resource.  A resource shorter than the fixed header is also
mapped as though it contained a complete header.

Reject resources shorter than the fixed header.  After validating the
signature, require a complete header, calculate the advertised extent
with overflow checking, and reject extents beyond the resource before
remapping the table.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
