Executive brief
A vulnerability in the Linux kernel's Intel i40e network driver could allow a user within a virtual machine to exhaust system resources. By requesting an unlimited number of network filters, a guest system could potentially cause a denial-of-service condition on the host server. This affects environments using Intel Ethernet 700 Series controllers with Virtual Functions enabled.
Technical details
A vulnerability in the i40e driver's Virtual Function (VF) interface allows a guest VM to request an arbitrary number of cloud filters. The function `i40e_vc_add_cloud_filter` in `drivers/net/ethernet/intel/i40e/i40e_virtchnl_pf.c` failed to validate the `num_cloud_filters` count against a maximum threshold. A local attacker with privileges to manage VF interfaces can exploit this to consume excessive kernel memory or hardware resources, leading to a Denial of Service (DoS). The fix introduces a hard limit of 0xFF00 (65280) filters per VF.
Affected products
- Linux Linux Kernel 4.17 to 6.11.x (fixed in 5.4.300, 5.10.245, 5.15.194, and others)
Timeline
- 2025-08-13: other: Patch authored by Intel
- 2025-10-02: patched: Patch committed to stable tree
- 2025-10-15: disclosed: CVE published
References
- https://git.kernel.org/stable/c/02aae5fcdd34c3a55a243d80a1b328a35852a35c
- https://git.kernel.org/stable/c/77a35be582dff4c80442ebcdce24d45eed8a6ce4
- https://git.kernel.org/stable/c/8b13df5aa877b9e4541e301a58a84c42d84d2d9a
- https://git.kernel.org/stable/c/9176e18681cb0d34c5acc87bda224f5652af2ab8
- https://git.kernel.org/stable/c/cb79fa7118c150c3c76a327894bb2eb878c02619
- https://git.kernel.org/stable/c/d33e5d6631ac4fddda235a7815babc9d3f124299
- https://git.kernel.org/stable/c/e490d8c5a54e0dd1ab22417d72c3a7319cf0f030