Executive brief
A vulnerability exists in the Linux drivers for Intel 800 Series Ethernet adapters, which are used to provide high-speed network connectivity for servers and workstations. A local user with basic access to the system could trigger a crash or system instability, leading to a denial of service. This could disrupt business operations by forcing the affected server to shut down or become unresponsive.
Technical details
A use-after-free vulnerability exists in the Intel 800 Series Ethernet Linux kernel driver (ice) before version 2.3.14. The flaw occurs within Ring 0 (kernel mode) and can be triggered by a local, authenticated user with low privileges. While the attack requires specific timing or environmental conditions (reflected in the 'Attack Terminated' or 'AT:P' CVSS metric), it does not require user interaction. Successful exploitation allows an attacker to cause a kernel panic or system hang, resulting in a complete loss of availability. This issue specifically affects Intel's out-of-tree drivers and does not impact the upstream Linux kernel driver.
Affected products
- Intel 800 Series Ethernet Linux Driver (ice) before 2.3.14
Timeline
- 2026-05-12: disclosed: Initial release of INTEL-SA-01426
- 2026-05-12: patched: Fix released in driver version 2.3.14