CVE-2025-39898Heap-based Buffer Overflow in Kernel

Severity
9.8CRITICAL
No vector
EPSS
No EPSS data
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 1
Latest updateOct 14

Description

e1000e: fix heap overflow in e1000_set_eeprom In the Linux kernel, the following vulnerability has been resolved: e1000e: fix heap overflow in e1000_set_eeprom Fix a possible heap overflow in e1000_set_eeprom function by adding input validation for the requested length of the change in the EEPROM. In addition, change the variable type from int to size_t for better code practices and rearrange declarations to RCT.

Affected Packages4 packages

🔴Vulnerability Details

3
OSV
e1000e: fix heap overflow in e1000_set_eeprom2025-10-01
GHSA
GHSA-46jx-rccq-85v5: In the Linux kernel, the following vulnerability has been resolved: e1000e: fix heap overflow in e1000_set_eeprom Fix a possible heap overflow in e12025-10-01
OSV
CVE-2025-39898: In the Linux kernel, the following vulnerability has been resolved: e1000e: fix heap overflow in e1000_set_eeprom Fix a possible heap overflow in e1002025-10-01

📋Vendor Advisories

2
Microsoft
e1000e: fix heap overflow in e1000_set_eeprom2025-10-14
Red Hat
kernel: e1000e: fix heap overflow in e1000_set_eeprom2025-10-01

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws2025-10-14
CVE-2025-39898 — Heap-based Buffer Overflow in Kernel | cvebase