PT-2026-2614 · Linux+3 · Linux Kernel+3

CVE-2025-71093

·

Published

2025-12-17

·

Updated

2026-08-30

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw within the e1000 network driver, specifically in the e1000 tbi should accept() function. This function improperly handles frame length validation, potentially leading to an out-of-bounds read when accessing the last byte of a frame. The issue occurs when the reported descriptor length is zero or exceeds the actual RX buffer size, causing a read to access unrelated slab objects. This condition was observed in the NAPI receive path (e1000 clean rx irq). The problematic code unconditionally dereferences the last byte of the frame without first validating the reported length.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09416
CVE-2025-71093
ECHO-5573-8A38-4641
MGASA-2026-0017
MGASA-2026-0018
OESA-2026-1275
OESA-2026-1276
OESA-2026-1303
OESA-2026-1304
OESA-2026-1305
OPENSUSE-SU-2026:20287-1
SUSE-SU-2026:0447-1
SUSE-SU-2026:0472-1
SUSE-SU-2026:0473-1
SUSE-SU-2026:0587-1
SUSE-SU-2026:20477-1
SUSE-SU-2026:20498-1
SUSE-SU-2026:20555-1
SUSE-SU-2026:20570-1
SUSE-SU-2026:20599-1
SUSE-SU-2026:20615-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
USN-8096-1
USN-8096-2
USN-8096-3
USN-8096-4
USN-8096-5
USN-8116-1
USN-8141-1
USN-8163-1
USN-8163-2
USN-8177-1
USN-8177-2
USN-8179-1
USN-8179-2
USN-8179-3
USN-8179-4
USN-8183-1
USN-8183-2
USN-8184-1
USN-8185-1
USN-8185-2
USN-8203-1
USN-8204-1
USN-8243-1
USN-8245-1
USN-8257-1
USN-8258-1
USN-8260-1
USN-8261-1
USN-8265-1
USN-8440-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu
E1000