Linux Kernel Integer Overflow Vulnerability in Marvell OCTEON TX Crypto Driver

Vulnerability

A vulnerability allowing integer overflows has been identified in the Linux kernel's Marvell OCTEON TX crypto driver. This issue arises from the 'code_length' value sourced from firmware files, which, if untrusted, can lead to potential exploitation. The vulnerability affects the stable versions of the Linux kernel.

Impact

Exploitation of this vulnerability could lead to undefined behavior in the kernel, potentially allowing for memory corruption or other malicious actions.

Reproduction

The vulnerability can be reproduced by loading a firmware file into the Marvell OCTEON TX crypto driver that contains a 'code_length' value designed to cause an overflow. This can be done by manipulating the firmware file to include an excessively large 'code_length' value, which the driver will not properly validate before use.

Remediation

Users can update to the latest version of the Linux kernel, where this vulnerability has been fixed. Instructions for updating the kernel can be found in the official Linux kernel documentation.

Added: Dec 24, 2025, 4:58 PM
Updated: Dec 24, 2025, 4:58 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.7
remediation
7.7
relevance
1.5
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.