net: prestera: validate firmware header length
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.2%
exploitation probability
0.2%top 89% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
net: prestera: validate firmware header length
prestera_fw_hdr_parse() reads the firmware header before checking
that the firmware image contains that header.
Reject images shorter than struct prestera_fw_header before decoding the
magic and version fields.
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/0fbcceb9d19f2d1dcdf099aee590f2517cb718bbhttps://git.kernel.org/stable/c/363e048a9d0a6c245cbc348c8a220170afed046ahttps://git.kernel.org/stable/c/38a3afbf9fd8a2e8c47fa3ca47b425a8a9623240https://git.kernel.org/stable/c/470ac9cce7308e60cf2dceb448749cdd006e73dehttps://git.kernel.org/stable/c/6fad06bb793d7089ae05b9fcf46e11be2dfe4850https://git.kernel.org/stable/c/7fa8a12296d8d5aa4b1c3904f0b354d81124cf29https://git.kernel.org/stable/c/8ae344eb540af3f457179b52bc6061416752485chttps://git.kernel.org/stable/c/e0f382e8084117f0b11ffb070fe1079e38c0d7f9