Out-of-bounds write in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
The vulnerability consists of an out-of-bounds write (CWE-787) in the Linux kernel-mode driver handling Intel Ethernet controllers and adapters. An attacker with local access to the system and regular user privileges can trigger an improper memory write operation in the kernel, which can lead to modification of critical operating system data structures. This makes it possible to obtain higher privileges than those the attacker originally possessed.
An authenticated local user can potentially obtain privilege escalation — in practice, it is possible to take full control of the operating system, including kernel-level access, which threatens the confidentiality, integrity, and availability of the entire system and related infrastructure.
The Linux driver for Intel Ethernet Network Controllers and Adapters should be updated to version 28.3 or later. Detailed information and patches are available in the Intel security advisory at: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00918.html
Linux kernel-mode driver for Intel Ethernet Network Controllers and Adapters prior to version 28.3 — affects devices with Intel Ethernet 800 Series Controllers Driver.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XIntel Ethernet 800 Series Controllers Driver
APPIntel< 28.3
Related vulnerabilities
Błąd wrap-around w sterowniku Intel Ethernet 800 — privilege escalation
Nieprawidłowa kontrola dostępu w sterowniku Intel Ethernet 800 Series — privilege escalation
Protection mechanism failure in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Ad...
Apache Log4j: niekompletna naprawa CVE-2021-44228 — RCE przez JNDI Lookup
Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup