Executive brief
A vulnerability was identified in the Linux kernel's Intel i40e network driver that could allow a local user to cause a system crash or potentially gain unauthorized access to sensitive information. The issue occurs when the system processes specific network queue configuration messages for virtual machines. Organizations using Intel Ethernet 700 Series controllers with virtualization enabled should apply the available kernel updates to maintain system stability and security.
Technical details
An out-of-bounds array access vulnerability exists in the i40e driver within the 'i40e_vc_config_queues_msg' function in 'drivers/net/ethernet/intel/i40e/i40e_virtchnl_pf.c'. The flaw stems from improper validation of the 'idx' parameter when Application Device Queues (ADq) are enabled, where the code checked against the total array size rather than the number of active Traffic Classes (TCs). A local attacker with low privileges can exploit this to access uninitialized or out-of-bounds memory when configuring Virtual Function (VF) queues. This issue has been resolved by ensuring the index is validated against 'vf->num_tc' in the affected code paths.
Affected products
- Linux Linux Kernel 4.17 to 6.11.2
Timeline
- 2025-08-13: other: Initial fix authored
- 2025-10-02: patched: Fix committed to stable kernel branches
- 2025-10-15: advisory: CVE published
References
- https://git.kernel.org/stable/c/1fa0aadade34481c567cdf4a897c0d4e4d548bd1
- https://git.kernel.org/stable/c/2cc26dac0518d2fa9b67ec813ee60e183480f98a
- https://git.kernel.org/stable/c/5c1f96123113e0bdc6d8dc2b0830184c93da9f65
- https://git.kernel.org/stable/c/8b9c7719b0987b1c6c5fc910599f3618a558dbde
- https://git.kernel.org/stable/c/a6ff2af78343eceb0f77ab1a2fe802183bc21648
- https://git.kernel.org/stable/c/bfcc1dff429d4b99ba03e40ddacc68ea4be2b32b
- https://git.kernel.org/stable/c/f1ad24c5abe1eaef69158bac1405a74b3c365115