Executive brief
A vulnerability in the Linux kernel's Intel Adaptive Virtual Function (iavf) network driver could allow a local user to cause a system crash. The issue occurs during network interface resets or disablement, where background tasks continue to run after their required memory has been freed. This can lead to unpredictable system behavior or a complete denial of service.
Technical details
A use-after-free vulnerability exists in the Linux kernel iavf driver due to a race condition between the PTP worker thread and the adapter reset/disable tasks. The worker thread, introduced to cache PHC (PTP Hardware Clock) time, is not properly synchronized or stopped during 'iavf_reset_task()' or 'iavf_disable_vf()'. Consequently, the worker may attempt to access adapter resources (Admin Queue) or locks after they have been freed. An attacker with local access could potentially exploit this race condition to cause a kernel panic or achieve arbitrary code execution. The fix involves calling 'iavf_ptp_release()' earlier in the teardown process to ensure the worker is synchronously cancelled before resources are destroyed.
Affected products
- Linux Linux Kernel 6.15 to 6.18.19, 6.19 to 6.19.9, 7.0-rc1 to 7.0-rc3
Timeline
- 2026-01-29: other: Patch authored
- 2026-03-10: patched: Initial patch committed to mainline
- 2026-05-08: disclosed: CVE published