Executive brief
The Intel ice network driver in the Linux kernel fails to properly release virtual switch interface (VSI) resources when resetting virtual functions (VFs) that have Flow Director filters enabled. This resource leak can degrade system memory and device performance over time, particularly in virtualized environments using Intel NICs with SR-IOV support.
Technical details
The vulnerability is a resource leak in the ice_reset_all_vfs() function in drivers/net/ethernet/intel/ice/ice_vf_lib.c. When resetting VFs with FDIR filters, the code incorrectly calls ice_vf_ctrl_invalidate_vsi() instead of ice_vf_ctrl_vsi_release(), leaving control VSI resources allocated but unreferenced. The bug affects systems running affected Linux kernel versions on Intel 100-series and later NICs with SR-IOV enabled. The fix involves a one-line change to use the proper resource release function, which has been patched in stable kernel releases. No user interaction or elevated privileges are required for the leak to occur—it triggers automatically when VFs are reset.
Affected products
- Linux Linux kernel Affects multiple versions; patched in stable branches
Timeline
- 2026-08-15: disclosed
- 2026-07-24: patched