Junglewise Threat Intelligence

CVE-2026-23389: Linux Kernel ice driver memory leak in ice_set_ringparam

CVE-2026-23389 · Severity: medium · CVSS 5.5 · Published 2026-03-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A memory leak vulnerability was identified in the Intel 'ice' network driver within the Linux kernel. This driver is responsible for managing high-speed Intel Ethernet network interfaces. An attacker with local access could potentially trigger this leak to exhaust system memory, leading to a denial-of-service condition where the system becomes unstable or crashes.

Technical details

A memory leak exists in the ice_set_ringparam() function within drivers/net/ethernet/intel/ice/ice_ethtool.c. The vulnerability occurs because tx_rings and xdp_rings are allocated before rx_rings; if the subsequent allocation or setup of rx_rings fails, the error handling paths (labels 'done' and 'free_tx') fail to release the previously allocated xdp_rings and/or tx_rings. This is a classic CWE-401 (Missing Release of Memory after Effective Lifetime) flaw. A local attacker can exploit this by repeatedly triggering failed ring parameter updates to exhaust kernel memory. Patches have been merged into various stable branches of the Linux kernel.

Affected products

  • Linux Linux Kernel 4.17 to 6.12.81, 6.13 to 6.18.22, 6.19 to 6.19.7, 7.0-rc1 to 7.0-rc7

Timeline

  • 2026-03-25: disclosed: Initial disclosure by kernel.org
  • 2026-03-25: advisory
  • 2026-03-12: patched: Patch committed to stable tree

References