kernel is vulnerable to Out-of-bounds Write. Given a sufficiently large number of actions, while copying and reserving memory for a new action of a new flow, the reserve_sfa_size()
function does not return -EMSGSIZE
as expected, potentially leading to an out-of-bounds write access which allows a local user to crash or potentially escalate their privileges on the system.