CVE-2025-39948
A critical vulnerability (CVE-2025-39948) in the Linux kernel's ice network driver causes a receive‑page leak when processing multi‑buffer frames that contain zero‑size descriptors. The leak occurs because the driver fails to free or reuse pages for those buffers, which can lead to memory exhaustion and potential reuse of stale pages. The issue affects kernel versions 6.14 and 6.17 and has a CVSS base score of 9.8.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel users running versions 6.14 or 6.17 with the ice driver enabled.
Real-world impact
Memory leak could degrade system performance or cause denial‑of‑service under heavy network traffic.
Why this severity
CVSS 9.8 (Critical) due to network‑adjacent, low‑complexity attack with high impact on confidentiality, integrity, and availability.
What to do about it
- 01Update the Linux kernel to a version that includes the ice driver fix for CVE-2025-39948 (the vulnerability has been marked as resolved in the kernel).
NVD-referenced vendor advisory (Linux kernel)
Timeline
- Oct 4, 2025 · Oct 4, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Jul 30, 2026 · 6d agoAdvisory updatedThe NVD record was last revised.
- Jul 30, 2026 · 6d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.