Junglewise Threat Intelligence

CVE-2026-80617: Linux kernel Airoha driver heap buffer overflow in foe_check_time allocation

CVE-2026-80617 · Severity: critical · CVSS 9.8 · Published 2026-08-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Airoha Ethernet driver in the Linux kernel contains a memory allocation bug that can cause a heap buffer overflow when processing network packets. When the packet forwarding engine verifies flow entries, it writes beyond an undersized buffer, leading to kernel crashes or potential system instability affecting devices using this network driver.

Technical details

The vulnerability is a heap buffer overflow in the Airoha PPE (packet processing engine) driver. The `foe_check_time` array is declared as a `u16` pointer but is allocated with only `ppe_num_entries` bytes instead of `ppe_num_entries * sizeof(u16)`. When the function `airoha_ppe_foe_verify_entry()` is called with a hash value greater than or equal to `ppe_num_entries/2`, it writes beyond the allocated buffer boundary. The fix changes the allocation to properly calculate the required memory: `ppe_num_entries * sizeof(*ppe->foe_check_time)`. No special privileges or network interaction are required; the overflow occurs during normal packet processing on systems with this driver compiled in.

Affected products

  • Linux Linux kernel 5.x, 6.x (versions with Airoha driver support)

Timeline

  • 2026-08-28: disclosed
  • 2026-06-18: patched: Upstream fix commit 5c121ee635680c93d7074becf14cfbaac140f80d

References

Related threats