Impact
The vulnerability arises in the Linux kernel’s Prestera networking driver, specifically in the firmware header parsing function. The parser reads the firmware header before confirming that the firmware image contains the expected header structure, creating a buffer over‑read if the image is truncated or malformed. This out‑of‑bounds read can corrupt kernel memory or trigger a fault, causing the kernel to crash and resulting in a denial of service. The weakness corresponds to the “Buffer over-read” category CWE‑125.
Affected Systems
All Linux kernels that include the Prestera driver are affected. Linux distributions shipping a kernel with this driver and who have not applied the recent patch are at risk. No specific kernel version range is cited, so the fix applies broadly to all actively maintained releases carrying the driver.
Risk and Exploitability
The CVSS score of 5.5 indicates medium severity. The EPSS score of less than 1 % suggests a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local: an attacker with the ability to load a firmware image—such as write permission on the Prestera firmware directory or a privileged firmware‑loading mechanism—could supply a malicious image that triggers the buffer over‑read, leading to a kernel fault or panic and thus denial of service.
OpenCVE Enrichment
Debian DLA
Debian DSA