Wrap-around error in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
The wrap-around error (CWE-128) consists of improper wrapping of numeric values during arithmetic calculations (CWE-682), which leads to errors in memory management or control logic in the Linux kernel mode driver. An attacker with local system access can exploit this impropriety to perform operations leading to privilege escalation in the kernel context of the operating system. The attack does not require user interaction or special system conditions.
An authenticated local user can obtain elevated privileges in the system, potentially reaching kernel privilege level, which enables complete takeover of the operating system and infrastructure resources.
The driver should be updated to version 28.3 or newer. Detailed information about available patches is available in the Intel security bulletin: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00918.html
Linux kernel mode driver for Intel Ethernet Network controllers and adapters (Intel Ethernet 800 series) in versions before 28.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XIntel Ethernet 800 Series Controllers Driver
APPIntel< 28.3
Related vulnerabilities
Out-of-bounds write w sterowniku Linux dla Intel Ethernet 800 Series — privilege escalation
Nieprawidłowa kontrola dostępu w sterowniku Intel Ethernet 800 Series — privilege escalation
Protection mechanism failure in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Ad...
Apache Log4j: niekompletna naprawa CVE-2021-44228 — RCE przez JNDI Lookup
Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup