Junglewise Threat Intelligence

CVE-2025-27723: Intel 800 Series Ethernet Linux Driver use-after-free in Ring 0

CVE-2025-27723 · Severity: info · CVSS 6.8 · Published 2026-05-12

Vendors: Intel.

Executive brief

A vulnerability exists in the Linux drivers for Intel 800 Series Ethernet adapters, which are used to provide high-speed network connectivity for servers and workstations. A local user with basic access to the system could trigger a crash or system instability, leading to a denial of service. This could disrupt business operations by forcing the affected server to shut down or become unresponsive.

Technical details

A use-after-free vulnerability exists in the Intel 800 Series Ethernet Linux kernel driver (ice) before version 2.3.14. The flaw occurs within Ring 0 (kernel mode) and can be triggered by a local, authenticated user with low privileges. While the attack requires specific timing or environmental conditions (reflected in the 'Attack Terminated' or 'AT:P' CVSS metric), it does not require user interaction. Successful exploitation allows an attacker to cause a kernel panic or system hang, resulting in a complete loss of availability. This issue specifically affects Intel's out-of-tree drivers and does not impact the upstream Linux kernel driver.

Affected products

  • Intel 800 Series Ethernet Linux Driver (ice) before 2.3.14

Timeline

  • 2026-05-12: disclosed: Initial release of INTEL-SA-01426
  • 2026-05-12: patched: Fix released in driver version 2.3.14

References