Executive brief
A vulnerability was identified in the Linux kernel's network driver for Texas Instruments AM65x Ethernet switches. The issue stems from incorrect memory allocation when processing incoming network data, which could lead to system instability or a crash. This primarily impacts the availability of the network service on affected hardware.
Technical details
A memory allocation vulnerability exists in the am65-cpsw-nuss driver within the Linux kernel. During a transition from netdev_alloc_ip_align() to build_skb(), the driver failed to account for the memory required by the skb_shared_info structure at the end of the socket buffer. This results in an undersized buffer allocation that does not include necessary space for headroom, tailroom, and shared info. An attacker could potentially trigger a kernel panic or memory corruption by sending network packets that exceed the improperly calculated buffer size. The issue has been resolved by ensuring PAGE_SIZE is used for the skb length in am65_cpsw_nuss_rx_packets.
Affected products
- Linux Linux Kernel 6.10 to 6.12.39, 6.13 to 6.15.7
Timeline
- 2025-08-16: disclosed
- 2025-08-16: advisory