CVE-2026-80617: Linux

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: net: airoha: fix foe_check_time allocation size foe_check_time is declared as u16 pointer but was allocated with only ppe_num_entries bytes instead of ppe_num_entries * sizeof(u16). When airoha_ppe_foe_verify_entry() is called with hash >= ppe_num_entries/2, it writes beyond the allocated buffer, causing heap buffer overflow and potential kernel crash.

Affected products

  • Linux Linux: from 6.18.33, before 6.18.40 (fixed in 6.18.40); from 6.19, before 7.1.5 (fixed in 7.1.5)

Published 2026-08-28. Last modified 2026-08-29.