SB2025032735 - Use-after-free in Linux kernel intel ice driver
Published: March 27, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use-after-free (CVE-ID: CVE-2025-21883)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the ice_initialize_vf_entry() function in drivers/net/ethernet/intel/ice/ice_vf_lib.c, within the ice_free_vf_entries() and ice_free_vfs() functions in drivers/net/ethernet/intel/ice/ice_sriov.c. A local user can escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/34393fd78d7183a007eaf0090966ebedcc29bd57
- https://git.kernel.org/stable/c/3c01102bec9592928e6b155da41cfcd5d25a2066
- https://git.kernel.org/stable/c/79990cf5e7aded76d0c092c9f5ed31eb1c75e02c
- https://git.kernel.org/stable/c/a4880583f88deba63504ce1c8287a70d39c01378
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.18