PT-2025-53068 · Intel+2 · 82580+5

Published

2023-09-13

·

Updated

2026-03-24

·

CVE-2023-54070

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contained a flaw in the igb driver related to Single Root I/O Virtualization (SR-IOV). Specifically, the cleanup process was incomplete when enabling SR-IOV, potentially leading to hangs or crashes when the igb module was removed, particularly on systems with 82580 network adapters. The issue stemmed from a failure in the pci enable sriov() function, causing the driver to incorrectly assume Virtual Functions (VFs) were set up when they were not. This was triggered by a commit that changed the error handling in igb enable sriov(). A reproducer script involving repeated module loading and unloading was identified to demonstrate the problem. The issue was observed on 82580 quad and dual-port adapters, but not on 82576, i350, and i210 adapters.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

BDU:2026-02063
CVE-2023-54070
RHSA-2024:2394
RHSA-2024:3138
SUSE-SU-2026:0263-1
SUSE-SU-2026:0278-1
SUSE-SU-2026:0281-1
SUSE-SU-2026:0293-1
SUSE-SU-2026:0315-1
SUSE-SU-2026:0316-1
SUSE-SU-2026:0317-1
SUSE-SU-2026:20477-1
SUSE-SU-2026:20498-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1

Affected Products

82576
82580
Linux Kernel
I210
I350
Igb