Executive brief
A vulnerability exists in the Linux kernel's DPAA2 network switch driver, which is used in certain high-performance networking hardware. The driver fails to properly check the number of network interfaces reported by the hardware's firmware, which can lead to memory corruption. An attacker with local access could potentially exploit this to crash the system or gain unauthorized elevated privileges.
Technical details
An out-of-bounds write vulnerability exists in the dpaa2-switch driver within the Linux kernel. The driver retrieves the 'num_ifs' attribute from firmware via dpsw_get_attributes() but fails to validate it against the DPSW_MAX_IF (64) limit. This value is subsequently used to control iterations in dpaa2_switch_fdb_get_flood_cfg(), which writes port indices into a fixed-size array (cfg->if_id[DPSW_MAX_IF]). If the firmware reports a value of 64 or greater, the loop overflows the array. This can result in kernel memory corruption. The issue has been addressed by adding a bounds check in dpaa2_switch_init().
Affected products
- Linux Linux Kernel 5.13 to 5.15.202, 5.16 to 6.1.165, 6.2 to 6.6.128, 6.7 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6, 7.0-rc1
Timeline
- 2026-02-24: other: Patch authored
- 2026-05-06: disclosed: CVE published
- 2026-05-06: advisory
References
- https://git.kernel.org/stable/c/89764cf44544e943230f5e03b8c40a90da26537c
- https://git.kernel.org/stable/c/8a5752c6dcc085a3bfc78589925182e4e98468c5
- https://git.kernel.org/stable/c/8b841fd529db9faf8bc678d429d4bf4e98b10900
- https://git.kernel.org/stable/c/a26dda3bae469c8e4e1b1993ad33dafa32d0fc28
- https://git.kernel.org/stable/c/a3034a8d56174dd6464c46823438f25797910a8d
- https://git.kernel.org/stable/c/b690635d4719214892855b79ce018d4b1672ac96
- https://git.kernel.org/stable/c/c18493f750208eb4ff1198fc5a02786b8b2d70a6