CVE-2025-21883
Linux Kernel vulnerability analysis and mitigation

Overview

A vulnerability in the Linux kernel's ice driver was discovered and disclosed on March 27, 2025. The issue occurs when ice_ena_vfs() fails after calling ice_create_vf_entries(), where it frees all VFs without removing them from the snapshot PF-VF mailbox list, leading to list corruption (NVD).

Technical details

The vulnerability manifests as a list corruption bug in the ice driver's VF management code. When ice_ena_vfs() fails after ice_create_vf_entries(), it incorrectly handles the cleanup process, resulting in a corrupted list state. The issue can be reproduced by manipulating the eswitch mode and SRIOV settings. The bug manifests either as a list_add corruption where next->prev should be prev but was found to be NULL, or as a KASAN use-after-free report in __list_add_valid_or_report (NVD, Snyk).

Impact

The vulnerability results in list corruption which can lead to system instability and potential denial of service. According to Red Hat's assessment, the vulnerability has a CVSS v3.1 base score of 5.5, indicating a medium severity impact with high availability impact but no loss of confidentiality or integrity (Red Hat).

Exploitability

The vulnerability requires local access to exploit, with low attack complexity and low privileges required. No user interaction is needed to trigger the vulnerability. The scope is unchanged, meaning the vulnerable component and the impacted component are managed by the same security authority (Snyk).

Mitigation and workarounds

The vulnerability has been resolved in the Linux kernel through a fix that moves the VF removal operation to ice_free_vf_entries(), which is called in various places where VFs are being removed, including ice_free_vfs() itself (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74583NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug
NoYesAug 21, 2026
CVE-2026-74582NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel.src
NoYesAug 21, 2026
CVE-2026-74581NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-modules-internal
NoYesAug 21, 2026
CVE-2026-74580NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug
NoYesAug 21, 2026
CVE-2025-30156NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel-matched
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management