{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-31699", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2026-03-09T15:48:24.131Z", "datePublished": "2026-05-01T13:55:59.520Z", "dateUpdated": "2026-08-05T12:24:36.729Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T12:24:36.729Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed\n\nWhen retrieving the PEK CSR, don't attempt to copy the blob to userspace\nif the firmware command failed. If the failure was due to an invalid\nlength, i.e. the userspace buffer+length was too small, copying the number\nof bytes _firmware_ requires will overflow the kernel-allocated buffer and\nleak data to userspace.\n\n BUG: KASAN: slab-out-of-bounds in instrument_copy_to_user ../include/linux/instrumented.h:129 [inline]\n BUG: KASAN: slab-out-of-bounds in _inline_copy_to_user ../include/linux/uaccess.h:205 [inline]\n BUG: KASAN: slab-out-of-bounds in _copy_to_user+0x66/0xa0 ../lib/usercopy.c:26\n Read of size 2084 at addr ffff898144612e20 by task syz.9.219/21405\n\n CPU: 14 UID: 0 PID: 21405 Comm: syz.9.219 Tainted: G U O 7.0.0-smp-DEV #28 PREEMPTLAZY\n Tainted: [U]=USER, [O]=OOT_MODULE\n Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 12.62.0-0 11/19/2025\n Call Trace:\n \n dump_stack_lvl+0xc5/0x110 ../lib/dump_stack.c:120\n print_address_description ../mm/kasan/report.c:378 [inline]\n print_report+0xbc/0x260 ../mm/kasan/report.c:482\n kasan_report+0xa2/0xe0 ../mm/kasan/report.c:595\n check_region_inline ../mm/kasan/generic.c:-1 [inline]\n kasan_check_range+0x264/0x2c0 ../mm/kasan/generic.c:200\n instrument_copy_to_user ../include/linux/instrumented.h:129 [inline]\n _inline_copy_to_user ../include/linux/uaccess.h:205 [inline]\n _copy_to_user+0x66/0xa0 ../lib/usercopy.c:26\n copy_to_user ../include/linux/uaccess.h:236 [inline]\n sev_ioctl_do_pek_csr+0x31f/0x590 ../drivers/crypto/ccp/sev-dev.c:1872\n sev_ioctl+0x3a4/0x490 ../drivers/crypto/ccp/sev-dev.c:2562\n vfs_ioctl ../fs/ioctl.c:51 [inline]\n __do_sys_ioctl ../fs/ioctl.c:597 [inline]\n __se_sys_ioctl+0x11d/0x1b0 ../fs/ioctl.c:583\n do_syscall_x64 ../arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0xe0/0x800 ../arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n \n\nWARN if the driver says the command succeeded, but the firmware error code\nsays otherwise, as __sev_do_cmd_locked() is expected to return -EIO on any\nfirwmware error." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The vulnerable code is reached through a local `ioctl(SEV_ISSUE_CMD)` on the `/dev/sev` misc character device with the `SEV_PEK_CSR` subcommand, not through a network or adjacent interface.\nAC:L - An attacker who can issue the ioctl can reliably trigger the bug by providing a CSR buffer length that is too small, causing firmware to return the required larger length. No race or condition outside the attacker's control is required.\nPR:L - The path requires write access to `/dev/sev`; the driver does not enforce a capability check, and reasonable SEV management deployments may delegate writable device access to non-root service or management accounts. Under the required higher-severity rule, this is scored as low privileges rather than root-only.\nUI:N - The attacker directly opens the device and issues the ioctl. No separate victim action is required.\nS:U - The bug affects kernel memory from a local kernel device interface within the same host security scope. It is not a VM escape, IOMMU bypass, or cross-authority boundary change.\nC:H - The old code copied the firmware-reported required CSR length from a smaller `kzalloc()` buffer, producing a slab out-of-bounds read into userspace. This can leak adjacent kernel heap data and is not limited to only a few bytes.\nI:N - The vulnerability is an out-of-bounds read during `copy_to_user()`, with no kernel memory write or direct control-flow corruption. It does not directly provide an integrity impact.\nA:H - The out-of-bounds usercopy is shown to trigger a KASAN slab-out-of-bounds BUG, and hardened/debug configurations can turn the invalid exposure into an oops or panic. It can be triggered repeatedly by issuing the ioctl again." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/crypto/ccp/sev-dev.c" ], "versions": [ { "version": "e799035609e1526761aa2f896a974b233d04d36d", "lessThan": "502d10a1d9d477e6c7fc7021a2dac7018f4ab8b5", "status": "affected", "versionType": "git" }, { "version": "e799035609e1526761aa2f896a974b233d04d36d", "lessThan": "0fb87e44b81385f940b482cba5b3f0bd18fb8185", "status": "affected", "versionType": "git" }, { "version": "e799035609e1526761aa2f896a974b233d04d36d", "lessThan": "372116eece159adff631b1508344c8b85ebf9559", "status": "affected", "versionType": "git" }, { "version": "e799035609e1526761aa2f896a974b233d04d36d", "lessThan": "607ba280f2adb5092cf5386c3935afac2ca0031a", "status": "affected", "versionType": "git" }, { "version": "e799035609e1526761aa2f896a974b233d04d36d", "lessThan": "59e9ae81f8670ccc780bc75f45a355736f640ec9", "status": "affected", "versionType": "git" }, { "version": "e799035609e1526761aa2f896a974b233d04d36d", "lessThan": "111dcc6d0f016076745824a787d25609d0022f4c", "status": "affected", "versionType": "git" }, { "version": "e799035609e1526761aa2f896a974b233d04d36d", "lessThan": "3b4fd8f15765d9a3105b834dba8a05d025e5e16e", "status": "affected", "versionType": "git" }, { "version": "e799035609e1526761aa2f896a974b233d04d36d", "lessThan": "abe4a6d6f606113251868c2c4a06ba904bb41eed", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/crypto/ccp/sev-dev.c" ], "versions": [ { "version": "4.16", "status": "affected" }, { "version": "0", "lessThan": "4.16", "status": "unaffected", "versionType": "semver" }, { "version": "5.10.258", "lessThanOrEqual": "5.10.*", "status": "unaffected", "versionType": "semver" }, { "version": "5.15.209", "lessThanOrEqual": "5.15.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.1.175", "lessThanOrEqual": "6.1.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.136", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.84", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.18.25", "lessThanOrEqual": "6.18.*", "status": "unaffected", "versionType": "semver" }, { "version": "7.0.2", "lessThanOrEqual": "7.0.*", "status": "unaffected", "versionType": "semver" }, { "version": "7.1", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.16", "versionEndExcluding": "5.10.258" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.16", "versionEndExcluding": "5.15.209" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.16", "versionEndExcluding": "6.1.175" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.16", "versionEndExcluding": "6.6.136" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.16", "versionEndExcluding": "6.12.84" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.16", "versionEndExcluding": "6.18.25" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.16", "versionEndExcluding": "7.0.2" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.16", "versionEndExcluding": "7.1" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/502d10a1d9d477e6c7fc7021a2dac7018f4ab8b5" }, { "url": "https://git.kernel.org/stable/c/0fb87e44b81385f940b482cba5b3f0bd18fb8185" }, { "url": "https://git.kernel.org/stable/c/372116eece159adff631b1508344c8b85ebf9559" }, { "url": "https://git.kernel.org/stable/c/607ba280f2adb5092cf5386c3935afac2ca0031a" }, { "url": "https://git.kernel.org/stable/c/59e9ae81f8670ccc780bc75f45a355736f640ec9" }, { "url": "https://git.kernel.org/stable/c/111dcc6d0f016076745824a787d25609d0022f4c" }, { "url": "https://git.kernel.org/stable/c/3b4fd8f15765d9a3105b834dba8a05d025e5e16e" }, { "url": "https://git.kernel.org/stable/c/abe4a6d6f606113251868c2c4a06ba904bb41eed" } ], "title": "crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed", "x_generator": { "engine": "bippy-1.2.0" } } } }