PT-2026-2614 · Intel+3 · E1000+3
Published
2026-01-13
·
Updated
2026-05-11
·
CVE-2025-71093
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The Linux kernel contains a flaw within the e1000 network driver, specifically in the
e1000 tbi should accept() function. This function improperly handles frame length validation, potentially leading to an out-of-bounds read when accessing the last byte of a frame. The issue occurs when the reported descriptor length is zero or exceeds the actual RX buffer size, causing a read to access unrelated slab objects. This condition was observed in the NAPI receive path (e1000 clean rx irq). The problematic code unconditionally dereferences the last byte of the frame without first validating the reported length.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu
E1000