Executive brief
A vulnerability in the Linux kernel's Intel 10G network driver (ixgbevf) could lead to system instability or crashes. The issue stems from a compatibility error in how the driver communicates between virtual and physical hardware components, specifically regarding security offloading features. If exploited, this could allow a local user to cause a denial of service or potentially gain unauthorized access to system resources.
Technical details
The vulnerability exists in the ixgbevf driver within the Linux kernel due to a breakdown in mailbox API backward compatibility starting with version 1.4. Specifically, the introduction of IPsec offload and ESX-specific mailbox communication in API versions 1.4 and 1.5 lacked proper feature negotiation mechanisms, leading to kernel crashes when a VF driver attempts to use unsupported features on certain PF drivers (such as the Linux ixgbe driver). An attacker with local access could trigger these code paths to cause a kernel panic or potentially exploit the resulting memory corruption. The fix introduces a new mailbox operation in API version 1.7 to explicitly negotiate supported features like IPsec and enhanced mailbox support before activation.
Affected products
- Linux Linux Kernel 4.20 to 6.1.158, 6.6.114, 6.12.y
Timeline
- 2025-10-20: patched: Initial patch submitted by Intel developers
- 2025-10-30: advisory: CVE-2025-40104 published
References
- https://git.kernel.org/stable/c/2e0aab9ddaf1428602c78f12064cd1e6ffcc4d18
- https://git.kernel.org/stable/c/871ac1cd4ce4804defcb428cbb003fd84c415ff4
- https://git.kernel.org/stable/c/a376e29b1b196dc90b50df7e5e3947e3026300c4
- https://git.kernel.org/stable/c/a7075f501bd33c93570af759b6f4302ef0175168
- https://git.kernel.org/stable/c/bf580112ed61736c2645a893413a04732505d4b1