CVE-2025-71093
A buffer over-read in the Linux kernel’s e1000 network driver allows an attacker to read memory beyond the receive buffer, potentially exposing sensitive data. The issue has been fixed in the kernel source. Updating to a kernel that includes this patch removes the risk.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
All Linux kernel users running the e1000 driver, including versions up to 6.19. Typical users are system administrators and end‑users on Linux machines with Intel e1000 network adapters.
Real-world impact
An attacker could read arbitrary memory, leading to information disclosure or system instability.
Why this severity
The CVSS score of 9.1 reflects that the flaw requires no authentication or user interaction, yet it can compromise confidentiality and availability by allowing an attacker to read memory and crash the system.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the e1000 driver fix.
NVD-referenced vendor advisory
Timeline
- Jan 13, 2026 · Jan 13, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 30, 2026 · 6d agoAdvisory updatedThe NVD record was last revised.
- Jul 30, 2026 · 6d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/26c8bebc2f25288c2b…patch
- git.kernel.org/stable/c/278b7cfe0d4da7502c…patch
- git.kernel.org/stable/c/2c4c0c09f9648ba766…patch
- git.kernel.org/stable/c/4ccfa56f272241e8d8…patch
- git.kernel.org/stable/c/9c72a5182ed92904d0…patch
- git.kernel.org/stable/c/ad7a2a45e2417ac540…patch
- git.kernel.org/stable/c/ee7c125fb3e8b04dd4…patch