Impact
In the Linux kernel, the airoha network driver incorrectly accounts inflight packets by counting only certain transmit queues while using completions from all queues, leading to a Buffer Queue Limit (BQL) imbalance. This flaw can cause the driver to throttle traffic improperly, resulting in packet loss, reduced throughput, and potentially a denial of service on the affected interface. The vulnerability is a logic error in resource accounting rather than an execution or authentication issue.
Affected Systems
The vulnerability impacts the Linux kernel on any system utilizing the airoha driver. No specific version information is listed in the CNA data, implying that any kernel revision prior to the inclusion of the listed patches may be affected.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not in CISA's KEV catalog. No public exploit is documented. The CVSS score is not supplied, so the severity cannot be quantified precisely, but the potential impact on network availability makes the risk moderate until the patch is applied. The likely attack vector, based on the description, involves an attacker who can direct traffic to the affected network device, such as by sending a high volume of packets that trigger the BQL imbalance, potentially from a host with network access to the interface.
OpenCVE Enrichment