Improper initialization in the Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
The vulnerability is an improper initialization (CWE-665) in the Linux kernel mode driver supporting selected Intel Ethernet controllers and adapters. Improper initialization can lead to inadequate privilege management (CWE-269), which a local authenticated user can exploit to gain elevated privileges on the system. The attack requires local access but does not require interaction from other users or special prerequisites beyond a basic user account.
An authenticated local user can achieve privilege escalation, potentially gaining full control over the operating system and affecting the security and availability of the environment in which the vulnerable driver operates.
The driver for Intel Ethernet network controllers and adapters should be updated to version 28.3 or later. Detailed information about available patches can be found in the official Intel security advisory: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00918.html
Linux kernel mode driver for selected Intel Ethernet network controllers and adapters in versions prior to 28.3.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X