Linux Kernel IAVF Driver Memory Leak Vulnerability

Vulnerability

A memory leak vulnerability has been identified in the Linux kernel's IAVF driver, specifically in the handling of dummy receive descriptors. When the hardware generates a dummy descriptor, the IAVF driver previously failed to free the associated memory from the prior receive buffer. Although this scenario is rare, it can occur. The vulnerability has been addressed by modifying the IAVF driver to properly manage memory for dummy receive descriptors.

Impact

Exploitation of this vulnerability leads to a memory leak, where allocated memory is not properly released, potentially causing increased memory usage over time.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.3
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.