Executive brief
A vulnerability was identified in the Linux kernel's Intermediate Functional Block (IFB) network driver. When a network device is configured with more receiving queues than transmitting queues, a system administrator requesting network statistics can trigger an out-of-bounds memory read. This could allow a local user with high privileges to view sensitive information from the system's memory that they should not have access to.
Technical details
A slab-out-of-bounds read exists in the Linux kernel's net/ifb driver. The `ifb_dev_init()` function allocates the `tx_private` array based on `dev->num_tx_queues`. However, the ethtool statistics callbacks (`ifb_get_ethtool_stats`, `ifb_get_strings`, and `ifb_get_sset_count`) incorrectly use `dev->real_num_rx_queues` and `dev->real_num_tx_queues` to iterate through these stats. In configurations where the number of RX queues exceeds the number of TX queues, the driver indexes past the allocated `tx_private` buffer. This allows a local attacker to leak adjacent slab data via the `ETHTOOL_GSTATS` ioctl. The issue has been patched by ensuring the driver consistently uses `dev->num_tx_queues` for all statistics operations.
Affected products
- Linux Linux Kernel v7.1-rc2
Timeline
- 2026-05-13: other: Patch authored
- 2026-07-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/16bd798cb6d8337d7c3eea1adc412f31b5181d5b
- https://git.kernel.org/stable/c/2638e1773904d7aa8f24c6e7fda2ed7d69df6fa4
- https://git.kernel.org/stable/c/301a554e458e2f5ec47f2c336a7cb03b877f9fd6
- https://git.kernel.org/stable/c/5db89c99566fc4728cc92e941d8e1975711e24b5
- https://git.kernel.org/stable/c/6afdb8113cb007f9332f59a9b7fd45731b8a9de5
- https://git.kernel.org/stable/c/f8a5a76b4a683043c6eff2a060bcaa17f9316ad5