Firmware Header Length Vulnerability in Linux Kernel Affecting Prestera
CVE-2026-74693
What is CVE-2026-74693?
A vulnerability in the Linux kernel's Prestera firmware processing allows for improper validation of firmware header lengths. The prestera_fw_hdr_parse() function does not verify that the firmware image has sufficient length before attempting to read its header. This oversight could potentially lead to the decoding of invalid or incomplete firmware, which may compromise system integrity and security. To mitigate this risk, it is essential to ensure that firmware images are validated against the expected struct prestera_fw_header length before decoding.
Affected Version(s)
Linux 4c2703dfd7fabb0824b3bc345f9fa47e33248c14 < 38a3afbf9fd8a2e8c47fa3ca47b425a8a9623240
Linux 4c2703dfd7fabb0824b3bc345f9fa47e33248c14 < 0fbcceb9d19f2d1dcdf099aee590f2517cb718bb
Linux 4c2703dfd7fabb0824b3bc345f9fa47e33248c14