CyberRota Analysis
AI-GeneratedA heap buffer overflow vulnerability exists in the Linux kernel's airoha driver due to incorrect memory allocation for the foe_check_time pointer, which is allocated insufficiently for its intended size. This flaw can lead to memory corruption, potentially resulting in a kernel crash and impacting system stability. Linux system administrators and developers using the affected kernel versions should prioritize applying patches to mitigate the risk of exploitation.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: net: airoha: fix foe_check_time allocation size foe_check_time is declared as u16 pointer but was allocated with only ppe_num_entries bytes instead of ppe_num_entries * sizeof(u16). When airoha_ppe_foe_verify_entry() is called with hash >= ppe_num_entries/2, it writes beyond the allocated buffer, causing heap buffer overflow and potential kernel crash.