Heap-based buffer overflow in Linux kernel - CVE-2026-80617
Published: August 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in airoha_ppe_foe_verify_entry() when processing a hash value greater than or equal to half of ppe_num_entries. A local user can trigger the vulnerable code path to cause a denial of service.
The issue is caused by allocating the foe_check_time buffer with too few bytes for u16 entries.