Executive brief
A vulnerability exists in the Linux kernel's i40e network driver, which manages certain Intel Ethernet controllers. A local attacker could exploit this flaw to cause a system crash or potentially gain unauthorized access to sensitive kernel memory. This issue stems from incorrect validation of user-supplied data when configuring network filters.
Technical details
An out-of-bounds (OOB) dereference vulnerability exists in the i40e driver within the 'i40e_validate_cloud_filter' function in 'drivers/net/ethernet/intel/i40e/i40e_virtchnl_pf.c'. The root cause is an off-by-one error in the input validation logic for 'action_meta', which represents a Traffic Class (TC) number. The code originally checked if the value was strictly greater than the number of TCs, but failed to account for zero-based indexing, requiring a 'greater than or equal' check instead. A local attacker with basic privileges can trigger this OOB access by submitting a cloud filter with an invalid TC index, potentially leading to a kernel panic or privilege escalation. Patches have been released across multiple stable kernel branches.
Affected products
- Linux Linux Kernel 4.17 to 6.11.x
Timeline
- 2025-08-13: other: Vulnerability fixed in source code
- 2025-10-15: advisory: CVE published by kernel.org
References
- https://git.kernel.org/stable/c/28465770ca3b694286ff9ed6dfd558413f57d98f
- https://git.kernel.org/stable/c/3118f41d8fa57b005f53ec3db2ba5eab1d7ba12b
- https://git.kernel.org/stable/c/3883e9702b6a4945e93b16c070f338a9f5b496f9
- https://git.kernel.org/stable/c/461e0917eedcd159d87f3ea846754a1e07d7e78a
- https://git.kernel.org/stable/c/560e1683410585fbd5df847f43433c4296f0d222
- https://git.kernel.org/stable/c/9739d5830497812b0bdeaee356ddefbe60830b88
- https://git.kernel.org/stable/c/a88c1b2746eccf00e2094b187945f0f1e990b400