CVE-2023-54070
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-54070 is a vulnerability in the Linux kernel's igb (Intel Gigabit Ethernet) driver related to improper cleanup in error paths when enabling SR-IOV (Single Root I/O Virtualization). The flaw was introduced after commit 50f303496d92 ("igb: Enable SR-IOV after reinit") and can cause the system to hang or crash when the igb module is removed while loaded with the max_vfs parameter set to a non-zero value. It was published on December 24, 2025, and affects the Linux kernel. The EPSS score is approximately 0.018% (very low), and no CVSS score has been publicly assigned as of the time of this report (Feedly).

Technical details

The root cause is improper resource cleanup (CWE-459: Incomplete Cleanup) in the igb driver's SR-IOV initialization code path. When the igb module is loaded with max_vfs != 0 and subsequently removed, error paths during SR-IOV enablement fail to properly clean up allocated resources, leading to PCIe bus errors including Unsupported Request (UnsupReq) errors and AER (Advanced Error Reporting) faults. The kernel logs show PCIe bus errors of severity "Uncorrected (Non-Fatal)" and the message "AER: can't recover (no error_detected callback)", ultimately causing a system hang or crash. The fix involves ensuring all error paths in the SR-IOV enablement routine perform complete cleanup (Feedly, Kernel Git).

Impact

Exploitation of this vulnerability results in a denial of service — specifically, a system hang or kernel crash — when the igb driver module is unloaded on systems using Intel 82580 or similar supported NICs with SR-IOV virtual functions enabled (max_vfs > 0). The impact is limited to availability; there is no evidence of confidentiality or integrity compromise. The affected scope is local to the host running the vulnerable kernel with the specific hardware and configuration (Feedly).

Mitigation and workarounds

Apply the upstream Linux kernel patches that address the incomplete cleanup in the igb SR-IOV error paths, referenced in the kernel stable tree commits 0e3ea7e82a06014b9baf1b84ba579c38cbff3558 and bc6ed2fa24b14e40e1005488bbe11268ce7108fa. As a workaround, avoid loading the igb module with max_vfs set to a non-zero value on affected hardware until the patch is applied. SUSE has issued advisories (SUSE-2026-0281-1 and SUSE-2026-20876-1) incorporating the fix for their kernel packages (Feedly, Linux Security SUSE).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management