roundup_pow_of_two of the component buddy. The manipulation results in allocation of resources.This vulnerability was named CVE-2026-43169. The attack needs to be approached within the local network. There is no available exploit.
You should upgrade the affected component.