{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.170-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.85-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.19.6-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  EFI/CPER: don't go past the ARM processor CPER record buffer  There's a logic inside GHES/CPER to detect if the section_length is too small, but it doesn't detect if it is too big.  Currently, if the firmware receives an ARM processor CPER record stating that a section length is big, kernel will blindly trust section_length, producing a very long dump. For instance, a 67 bytes record with ERR_INFO_NUM set 46198 and section length set to 854918320 would dump a lot of data going a way past the firmware memory-mapped area.  Fix it by adding a logic to prevent it to go past the buffer if ERR_INFO_NUM is too big, making it report instead:  \t[Hardware Error]: Hardware error from APEI Generic Hardware Error Source: 1 \t[Hardware Error]: event severity: recoverable \t[Hardware Error]:  Error 0, type: recoverable \t[Hardware Error]:   section_type: ARM processor error \t[Hardware Error]:   MIDR: 0xff304b2f8476870a \t[Hardware Error]:   section length: 854918320, CPER size: 67 \t[Hardware Error]:   section length is too big \t[Hardware Error]:   firmware-generated error record is incorrect \t[Hardware Error]:   ERR_INFO_NUM is 46198  [ rjw: Subject and changelog tweaks ]",
  "id": "DEBIAN-CVE-2026-43266",
  "modified": "2026-09-14T16:47:49.562249588Z",
  "published": "2026-05-06T12:16:47.647Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-43266"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-43266"
  ]
}