Insufficient Control Flow in Intel Ethernet Driver Affects Linux Systems
CVE-2025-22893

8.8HIGH

Key Information:

Vendor

Intel

Vendor
CVE Published:
12 August 2025

What is CVE-2025-22893?

The Linux kernel-mode driver for Intel's 800 Series Ethernet contains an insufficient control flow management flaw that allows authenticated users to escalate privileges through local access. This vulnerability has been identified in versions prior to 1.17.2 of the driver, emphasizing the need for organizations using affected systems to stay informed and apply the latest security updates.

Affected Version(s)

Intel(R) 800 Series Ethernet before version 1.17.2

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.