{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2023-54166",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2025-12-30T12:06:44.495Z",
        "datePublished": "2025-12-30T12:08:41.832Z",
        "dateUpdated": "2026-08-05T09:17:47.971Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T09:17:47.971Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nigc: Fix Kernel Panic during ndo_tx_timeout callback\n\nThe Xeon validation group has been carrying out some loaded tests\nwith various HW configurations, and they have seen some transmit\nqueue time out happening during the test. This will cause the\nreset adapter function to be called by igc_tx_timeout().\nSimilar race conditions may arise when the interface is being brought\ndown and up in igc_reinit_locked(), an interrupt being generated, and\nigc_clean_tx_irq() being called to complete the TX.\n\nWhen the igc_tx_timeout() function is invoked, this patch will turn\noff all TX ring HW queues during igc_down() process. TX ring HW queues\nwill be activated again during the igc_configure_tx_ring() process\nwhen performing the igc_up() procedure later.\n\nThis patch also moved existing igc_disable_tx_ring_hw() to avoid using\nforward declaration.\n\nKernel trace:\n[ 7678.747813] ------------[ cut here ]------------\n[ 7678.757914] NETDEV WATCHDOG: enp1s0 (igc): transmit queue 2 timed out\n[ 7678.770117] WARNING: CPU: 0 PID: 13 at net/sched/sch_generic.c:525 dev_watchdog+0x1ae/0x1f0\n[ 7678.784459] Modules linked in: xt_conntrack nft_chain_nat xt_MASQUERADE xt_addrtype nft_compat\nnf_tables nfnetlink br_netfilter bridge stp llc overlay dm_mod emrcha(PO) emriio(PO) rktpm(PO)\ncegbuf_mod(PO) patch_update(PO) se(PO) sgx_tgts(PO) mktme(PO) keylocker(PO) svtdx(PO) svfs_pci_hotplug(PO)\nvtd_mod(PO) davemem(PO) svmabort(PO) svindexio(PO) usbx2(PO) ehci_sched(PO) svheartbeat(PO) ioapic(PO)\nsv8259(PO) svintr(PO) lt(PO) pcierootport(PO) enginefw_mod(PO) ata(PO) smbus(PO) spiflash_cdf(PO) arden(PO)\ndsa_iax(PO) oobmsm_punit(PO) cpm(PO) svkdb(PO) ebg_pch(PO) pch(PO) sviotargets(PO) svbdf(PO) svmem(PO)\nsvbios(PO) dram(PO) svtsc(PO) targets(PO) superio(PO) svkernel(PO) cswitch(PO) mcf(PO) pentiumIII_mod(PO)\nfs_svfs(PO) mdevdefdb(PO) svfs_os_services(O) ixgbe mdio mdio_devres libphy emeraldrapids_svdefs(PO)\nregsupport(O) libnvdimm nls_cp437 snd_hda_codec_realtek snd_hda_codec_generic ledtrig_audio snd_hda_intel\nsnd_intel_dspcfg snd_hda_codec snd_hwdep x86_pkg_temp_thermal snd_hda_core snd_pcm snd_timer isst_if_mbox_pci\n[ 7678.784496]  input_leds isst_if_mmio sg snd isst_if_common soundcore wmi button sad9(O) drm fuse backlight\nconfigfs efivarfs ip_tables x_tables vmd sdhci led_class rtl8150 r8152 hid_generic pegasus mmc_block usbhid\nmmc_core hid megaraid_sas ixgb igb i2c_algo_bit ice i40e hpsa scsi_transport_sas e1000e e1000 e100 ax88179_178a\nusbnet xhci_pci sd_mod xhci_hcd t10_pi crc32c_intel crc64_rocksoft igc crc64 crc_t10dif usbcore\ncrct10dif_generic ptp crct10dif_common usb_common pps_core\n[ 7679.200403] RIP: 0010:dev_watchdog+0x1ae/0x1f0\n[ 7679.210201] Code: 28 e9 53 ff ff ff 4c 89 e7 c6 05 06 42 b9 00 01 e8 17 d1 fb ff 44 89 e9 4c\n89 e6 48 c7 c7 40 ad fb 81 48 89 c2 e8 52 62 82 ff <0f> 0b e9 72 ff ff ff 65 8b 05 80 7d 7c 7e\n89 c0 48 0f a3 05 0a c1\n[ 7679.245438] RSP: 0018:ffa00000001f7d90 EFLAGS: 00010282\n[ 7679.256021] RAX: 0000000000000000 RBX: ff11000109938440 RCX: 0000000000000000\n[ 7679.268710] RDX: ff11000361e26cd8 RSI: ff11000361e1b880 RDI: ff11000361e1b880\n[ 7679.281314] RBP: ffa00000001f7da8 R08: ff1100035f8fffe8 R09: 0000000000027ffb\n[ 7679.293840] R10: 0000000000001f0a R11: ff1100035f840000 R12: ff11000109938000\n[ 7679.306276] R13: 0000000000000002 R14: dead000000000122 R15: ffa00000001f7e18\n[ 7679.318648] FS:  0000000000000000(0000) GS:ff11000361e00000(0000) knlGS:0000000000000000\n[ 7679.332064] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 7679.342757] CR2: 00007ffff7fca168 CR3: 000000013b08a006 CR4: 0000000000471ef8\n[ 7679.354984] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 7679.367207] DR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400\n[ 7679.379370] PKRU: 55555554\n[ 7679.386446] Call Trace:\n[ 7679.393152]  <TASK>\n[ 7679.399363]  ? __pfx_dev_watchdog+0x10/0x10\n[ 7679.407870]  call_timer_fn+0x31/0x110\n[ 7679.415698]  e\n---truncated---"
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The defect lives in the igc driver's local down/reset and TX-completion paths (`igc_down()` vs `igc_clean_tx_irq()`), reached through local netdev lifecycle operations and locally generated transmit traffic, not by parsing data received from a remote peer. A remote peer can only indirectly induce host TX load, so Local is the correct access vector.\nAC:L - The attacker controls the racing side — sustained local transmit traffic keeps socket-owned skbs in flight and `igc_clean_tx_irq()` firing — while the window is enormous rather than narrow: the HW TX queues stay enabled across a 10–20 ms sleep, a full `igc_reset()`, the skb free loop, the ring/BQL memset, and the re-arm in `igc_up()`. `igc_tx_timeout()` even writes `IGC_EICS` to force interrupts on every queue, so the colliding NAPI poll is generated by the driver itself; repeated reinit cycles under load hit it reliably.\nPR:L - No capability check exists anywhere on the path from packet transmission → stalled queue → `dev_watchdog` → `igc_tx_timeout()` → `igc_reset_task()` → `igc_down()`, so an unprivileged local account generating load drives the whole sequence; the reinit variant needs only namespace-level CAP_NET_ADMIN over a delegated netdev rather than init-namespace root. This matches the scoring of the equivalent mlx5e tx-timeout race (CVE-2024-45019) and ice tx_buf double-free (CVE-2026-53009).\nUI:N - The reset runs from the kernel watchdog timer and `igc_reset_task()` workqueue, and the completion path runs in softirq/NAPI context. No victim action of any kind is required.\nS:U - The corrupted objects (`sk_buff`, `struct sock`, `igc_ring`/`igc_tx_buffer` state, the dql counters) all belong to the host kernel's own security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - The double `napi_consume_skb()` on an already-freed skb plus the `sock` refcount underflow confirmed in the `tcp_wfree` trace is a genuine use-after-free on slab objects the attacker can groom by controlling socket and skb allocation. Such a UAF read primitive can be leveraged to disclose kernel memory.\nI:H - A double-free of an skb and a refcount underflow on `struct sock` corrupt allocator metadata and leave a freed socket still referenced, which is a standard heap-corruption primitive shapeable into an arbitrary write or control-flow hijack. Under conservative scoring this warrants High integrity impact.\nA:H - The commit is literally titled \"Fix Kernel Panic\" and the reported outcome is a `BUG_ON` in `dql_completed()` taken in interrupt context — \"PANIC: Fatal exception in interrupt\" — a complete, unrecoverable system crash. The use-after-free independently produces oopses and slab corruption even when not fully exploited."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/net/ethernet/intel/igc/igc_main.c"
                    ],
                    "versions": [
                        {
                            "version": "48d6d8f2f6096ef51bd193e2a2fb59cbbc350599",
                            "lessThan": "feba294c454a51bb1e80dd2ff038e335f07ae481",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "5f9c656ab2c4c36f3b85819c7a9a8bec5711cfb5",
                            "lessThan": "c09df09241fdd6aa5b94a5243369662a13ec608a",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "9b275176270efd18f2f4e328b32be1bad34c4c0d",
                            "lessThan": "c12554d97fcd954d5c66bcd016586732cf240d0b",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "9b275176270efd18f2f4e328b32be1bad34c4c0d",
                            "lessThan": "d4a7ce642100765119a872d4aba1bf63e3a22c8a",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "5.15.94",
                            "lessThan": "5.15.124",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.12",
                            "lessThan": "6.1.43",
                            "status": "affected",
                            "versionType": "semver"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/net/ethernet/intel/igc/igc_main.c"
                    ],
                    "versions": [
                        {
                            "version": "6.2",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "6.2",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.124",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.43",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.4.8",
                            "lessThanOrEqual": "6.4.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.5",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.15.94",
                                    "versionEndExcluding": "5.15.124"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.1.12",
                                    "versionEndExcluding": "6.1.43"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.2",
                                    "versionEndExcluding": "6.4.8"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.2",
                                    "versionEndExcluding": "6.5"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/feba294c454a51bb1e80dd2ff038e335f07ae481"
                },
                {
                    "url": "https://git.kernel.org/stable/c/c09df09241fdd6aa5b94a5243369662a13ec608a"
                },
                {
                    "url": "https://git.kernel.org/stable/c/c12554d97fcd954d5c66bcd016586732cf240d0b"
                },
                {
                    "url": "https://git.kernel.org/stable/c/d4a7ce642100765119a872d4aba1bf63e3a22c8a"
                }
            ],
            "title": "igc: Fix Kernel Panic during ndo_tx_timeout callback",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}