Impact
The vulnerability occurs in the Linux kernel's ice driver. During initialization of a parser profile, an out‑of‑range ptype value supplied via VIRTCHNL allows a malicious virtual function to write past the end of a 1024‑bit bitmap, causing a kernel page fault. This results in a kernel Oops and a sudden system crash, effectively denying service to the host.
Affected Systems
The affected product is the Linux kernel with the ice driver included. Versions that compile the ice driver and expose the VIRTCHNL interface are susceptible; the defect was reproduced on a 7.1.0‑rc1 kernel but applies to all builds with the unpatched ice module.
Risk and Exploitability
A direct kernel crash is the only impact; there is no evidence of arbitrary code execution. Because the exploit requires control over a virtual function interface, it is limited to attackers who can inject traffic into VIRTCHNL. The CVSS score is 8.8 and the EPSS score is <1%, indicating a high severity and a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, but the risk is elevated for environments where VIRTCHNL traffic can be controlled, as the crash could disrupt services or require a reboot.
OpenCVE Enrichment
Debian DLA