{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-31697", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2026-03-09T15:48:24.131Z", "datePublished": "2026-05-01T13:55:58.184Z", "dateUpdated": "2026-08-05T12:24:34.586Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T12:24:34.586Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp: Don't attempt to copy ID to userspace if PSP command failed\n\nWhen retrieving the ID for the CPU, don't attempt to copy the ID blob to\nuserspace if the firmware command failed. If the failure was due to an\ninvalid length, i.e. the userspace buffer+length was too small, copying\nthe number of bytes _firmware_ requires will overflow the kernel-allocated\nbuffer and leak data to userspace.\n\n BUG: KASAN: slab-out-of-bounds in instrument_copy_to_user ../include/linux/instrumented.h:129 [inline]\n BUG: KASAN: slab-out-of-bounds in _inline_copy_to_user ../include/linux/uaccess.h:205 [inline]\n BUG: KASAN: slab-out-of-bounds in _copy_to_user+0x66/0xa0 ../lib/usercopy.c:26\n Read of size 64 at addr ffff8881867f5960 by task syz.0.906/24388\n\n CPU: 130 UID: 0 PID: 24388 Comm: syz.0.906 Tainted: G U O 7.0.0-smp-DEV #28 PREEMPTLAZY\n Tainted: [U]=USER, [O]=OOT_MODULE\n Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 12.62.0-0 11/19/2025\n Call Trace:\n \n dump_stack_lvl+0xc5/0x110 ../lib/dump_stack.c:120\n print_address_description ../mm/kasan/report.c:378 [inline]\n print_report+0xbc/0x260 ../mm/kasan/report.c:482\n kasan_report+0xa2/0xe0 ../mm/kasan/report.c:595\n check_region_inline ../mm/kasan/generic.c:-1 [inline]\n kasan_check_range+0x264/0x2c0 ../mm/kasan/generic.c:200\n instrument_copy_to_user ../include/linux/instrumented.h:129 [inline]\n _inline_copy_to_user ../include/linux/uaccess.h:205 [inline]\n _copy_to_user+0x66/0xa0 ../lib/usercopy.c:26\n copy_to_user ../include/linux/uaccess.h:236 [inline]\n sev_ioctl_do_get_id2+0x361/0x490 ../drivers/crypto/ccp/sev-dev.c:2222\n sev_ioctl+0x25f/0x490 ../drivers/crypto/ccp/sev-dev.c:2575\n vfs_ioctl ../fs/ioctl.c:51 [inline]\n __do_sys_ioctl ../fs/ioctl.c:597 [inline]\n __se_sys_ioctl+0x11d/0x1b0 ../fs/ioctl.c:583\n do_syscall_x64 ../arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0xe0/0x800 ../arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n \n\nWARN if the driver says the command succeeded, but the firmware error code\nsays otherwise, as __sev_do_cmd_locked() is expected to return -EIO on any\nfirwmware error." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The vulnerable path is reached through a local ioctl on the host `/dev/sev` misc device using `SEV_ISSUE_CMD` with `SEV_GET_ID2`; it is not reachable from network packets or from SEV guests.\nAC:L - The attacker controls the supplied buffer length and can reliably make firmware return an invalid-length error that updates `data.len` beyond the allocated buffer size. No race or uncontrollable heap condition is required to trigger the out-of-bounds copy.\nPR:L - Access requires permission to open `/dev/sev`, which defaults restrictive but is reasonably granted to non-root virtualization users or service accounts via device policy. The ioctl command itself has no capability check and `SEV_GET_ID2` does not require write access.\nUI:N - Once the attacker has local access to the device node, exploitation is a direct ioctl call. No victim action is required.\nS:U - The vulnerability is in the host kernel SEV/PSP driver and impacts host kernel memory and availability within the same security authority. It is not a guest-to-host escape or IOMMU/DMA boundary bypass.\nC:H - The bug copies firmware-reported length bytes from a smaller `kzalloc()` buffer to userspace, leaking adjacent kernel heap memory. Under the requested high-severity tie-break rule, this out-of-bounds kernel read is High confidentiality impact.\nI:N - The flawed operation is an over-read from kernel memory during `copy_to_user()`. It does not write to kernel memory or provide a demonstrated data-modification primitive.\nA:H - The same out-of-bounds usercopy can trigger kernel hardening or sanitizer failures, and hardened usercopy aborts such invalid slab exposures with a BUG. This makes a kernel crash reasonably defensible." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/crypto/ccp/sev-dev.c" ], "versions": [ { "version": "d6112ea0cb344d6f5ed519991e24f69ba4b43d0e", "lessThan": "99bae2e3c3f9ba8f854c938ed2c811b6a63b28e4", "status": "affected", "versionType": "git" }, { "version": "d6112ea0cb344d6f5ed519991e24f69ba4b43d0e", "lessThan": "a21ae9f8769e5f75433bb0a85ac3868b2100ef5b", "status": "affected", "versionType": "git" }, { "version": "d6112ea0cb344d6f5ed519991e24f69ba4b43d0e", "lessThan": "0f1f2f9894893dc8a28af1b9e9dbc0abf453eb52", "status": "affected", "versionType": "git" }, { "version": "d6112ea0cb344d6f5ed519991e24f69ba4b43d0e", "lessThan": "09427bcb1715fb20a80b6acd5156dbf15ab5c363", "status": "affected", "versionType": "git" }, { "version": "d6112ea0cb344d6f5ed519991e24f69ba4b43d0e", "lessThan": "1fbac0429a42adec830491757a2b53956dd797ea", "status": "affected", "versionType": "git" }, { "version": "d6112ea0cb344d6f5ed519991e24f69ba4b43d0e", "lessThan": "2937f17bbeefb8e7608ff1f78cffbeb3d0281e5e", "status": "affected", "versionType": "git" }, { "version": "d6112ea0cb344d6f5ed519991e24f69ba4b43d0e", "lessThan": "06f06d88c05ce176c61fff8c72c372847b0dd2b5", "status": "affected", "versionType": "git" }, { "version": "d6112ea0cb344d6f5ed519991e24f69ba4b43d0e", "lessThan": "4f685dbfa87c546e51d9dc6cab379d20f275e114", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/crypto/ccp/sev-dev.c" ], "versions": [ { "version": "5.2", "status": "affected" }, { "version": "0", "lessThan": "5.2", "status": "unaffected", "versionType": "semver" }, { "version": "5.10.258", "lessThanOrEqual": "5.10.*", "status": "unaffected", "versionType": "semver" }, { "version": "5.15.209", "lessThanOrEqual": "5.15.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.1.175", "lessThanOrEqual": "6.1.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.136", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.84", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.18.25", "lessThanOrEqual": "6.18.*", "status": "unaffected", "versionType": "semver" }, { "version": "7.0.2", "lessThanOrEqual": "7.0.*", "status": "unaffected", "versionType": "semver" }, { "version": "7.1", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.2", "versionEndExcluding": "5.10.258" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.2", "versionEndExcluding": "5.15.209" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.2", "versionEndExcluding": "6.1.175" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.2", "versionEndExcluding": "6.6.136" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.2", "versionEndExcluding": "6.12.84" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.2", "versionEndExcluding": "6.18.25" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.2", "versionEndExcluding": "7.0.2" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.2", "versionEndExcluding": "7.1" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/99bae2e3c3f9ba8f854c938ed2c811b6a63b28e4" }, { "url": "https://git.kernel.org/stable/c/a21ae9f8769e5f75433bb0a85ac3868b2100ef5b" }, { "url": "https://git.kernel.org/stable/c/0f1f2f9894893dc8a28af1b9e9dbc0abf453eb52" }, { "url": "https://git.kernel.org/stable/c/09427bcb1715fb20a80b6acd5156dbf15ab5c363" }, { "url": "https://git.kernel.org/stable/c/1fbac0429a42adec830491757a2b53956dd797ea" }, { "url": "https://git.kernel.org/stable/c/2937f17bbeefb8e7608ff1f78cffbeb3d0281e5e" }, { "url": "https://git.kernel.org/stable/c/06f06d88c05ce176c61fff8c72c372847b0dd2b5" }, { "url": "https://git.kernel.org/stable/c/4f685dbfa87c546e51d9dc6cab379d20f275e114" } ], "title": "crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed", "x_generator": { "engine": "bippy-1.2.0" } } } }