Impact
The ixgbevf driver contains a use‑after‑free bug caused by skipping a pointer reset after freeing. This flaw, classified as CWE‑825, can lead to arbitrary kernel memory corruption when memory is reused in a NAPI softirq context, potentially enabling privilege escalation.
Affected Systems
All Linux kernel releases that ship the buggy ixgbevf driver code for Intel 10/25Gb network adapters in virtualized environments are affected. The specific kernel versions are not listed in the CVE data.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, yet the EPSS score of less than 1% suggests few active exploits at this time. Because the flaw occurs in a driver that processes external network traffic, the likely attack vector is remote network traffic directed at a vulnerable VM; this inference is based on the description that the vulnerability occurs in a driver handling network traffic. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Ubuntu USN