SB20251226168 - Out-of-bounds read in Linux kernel intel ixgbe driver
Published: December 26, 2025 Updated: December 31, 2025
Security Bulletin ID
SB20251226168
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2023-54090)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds read error within the ixgbe_sw_init() and ixgbe_xdp_setup() functions in drivers/net/ethernet/intel/ixgbe/ixgbe_main.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1924450175349e64f8dfc3689efcb653dba0418e
- https://git.kernel.org/stable/c/4cd43a19900d0b98c1ec4bb6984763369d2e19ec
- https://git.kernel.org/stable/c/785b2b5b47b1aa4c31862948b312ea845401c5ec
- https://git.kernel.org/stable/c/c23ae5091a8b3e50fe755257df020907e7c029bb
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.29
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2.16
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.3.3
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.4