Executive brief
A vulnerability exists in the Linux kernel's e1000 network driver, which is used to manage Intel Ethernet adapters. An attacker could potentially send specially crafted network traffic that causes the system to read memory outside of the intended buffer. This could lead to system instability, crashes, or the exposure of sensitive information stored in the computer's memory.
Technical details
An out-of-bounds (OOB) read vulnerability exists in the e1000 driver within the Linux kernel. The root cause is located in the e1000_tbi_should_accept() function, which unconditionally dereferences the last byte of a received frame (data[length - 1]) to evaluate a Ten Bit Interface (TBI) workaround without first validating the descriptor-reported length. If the reported length is zero or exceeds the actual RX buffer size (adapter->rx_buffer_len), the driver reads memory from unrelated slab objects. This vulnerability is reachable via the NAPI receive path (e1000_clean_rx_irq) and can be triggered by network traffic. Patches have been released for various stable kernel branches to implement proper length validation before memory access.
Affected products
- Linux Linux Kernel versions using e1000 driver
Timeline
- 2025-12-01: disclosed: Vulnerability reported and patch authored by Guangshuo Li
- 2026-01-08: patched: Patch committed to stable kernel tree
- 2026-01-13: advisory: CVE published to NVD
References
- https://git.kernel.org/stable/c/26c8bebc2f25288c2bcac7bc0a7662279a0e817c
- https://git.kernel.org/stable/c/278b7cfe0d4da7502c7fd679b15032f014c92892
- https://git.kernel.org/stable/c/2c4c0c09f9648ba766d399917d420d03e7b3e1f8
- https://git.kernel.org/stable/c/4ccfa56f272241e8d8e2c38191fdbb03df489d80
- https://git.kernel.org/stable/c/9c72a5182ed92904d01057f208c390a303f00a0f
- https://git.kernel.org/stable/c/ad7a2a45e2417ac54089926b520924f8f0d91aea
- https://git.kernel.org/stable/c/ee7c125fb3e8b04dd46510130b9fc92380e5d578