cbcvebase.
CVE-2025-39973
published 2025-10-15

CVE-2025-39973: In the Linux kernel, the following vulnerability has been resolved: i40e: add validation for ring_len param The `ring_len` parameter provided by the virtual…

PriorityP345high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.14%
4.2th percentile
In the Linux kernel, the following vulnerability has been resolved: i40e: add validation for ring_len param The `ring_len` parameter provided by the virtual function (VF) is assigned directly to the hardware memory context (HMC) without any validation. To address this, introduce an upper boundary check for both Tx and Rx queue lengths. The maximum number of descriptors supported by the hardware is 8k-32. Additionally, enforce alignment constraints: Tx rings must be a multiple of 8, and Rx rings must be a multiple of 32.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= 5c3c48ac6bf56367c4e89f6453cd2d61e50375bd < 0543d40d6513cdf1c7882811086e59a6455dfe970543d40d6513cdf1c7882811086e59a6455dfe97
linuxlinux>= 5c3c48ac6bf56367c4e89f6453cd2d61e50375bd < 7d749e38dd2b7e8a80da2ca30c93e09de95bfcf97d749e38dd2b7e8a80da2ca30c93e09de95bfcf9
linuxlinux>= 5c3c48ac6bf56367c4e89f6453cd2d61e50375bd < 45a7527cd7da4cdcf3b06b5c0cb1cae30b5a598545a7527cd7da4cdcf3b06b5c0cb1cae30b5a5985
linuxlinux>= 5c3c48ac6bf56367c4e89f6453cd2d61e50375bd < d3b0d3f8d11fa957171fbb186e53998361a88d4ed3b0d3f8d11fa957171fbb186e53998361a88d4e
linuxlinux>= 5c3c48ac6bf56367c4e89f6453cd2d61e50375bd < c0c83f4cd074b75cecef107bfc349be7d516c9c4c0c83f4cd074b75cecef107bfc349be7d516c9c4
linuxlinux>= 5c3c48ac6bf56367c4e89f6453cd2d61e50375bd < 05fe81fb9db20464fa532a3835dc8300d68a2f8405fe81fb9db20464fa532a3835dc8300d68a2f84
linuxlinux>= 5c3c48ac6bf56367c4e89f6453cd2d61e50375bd < afec12adab55d10708179a64d95d650741e60fe0afec12adab55d10708179a64d95d650741e60fe0
linuxlinux>= 5c3c48ac6bf56367c4e89f6453cd2d61e50375bd < 55d225670def06b01af2e7a5e0446fbe946289e855d225670def06b01af2e7a5e0446fbe946289e8
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.16.10-16.16.10-1
linuxlinux_kernel>= 0 < 5.15.0-170.1805.15.0-170.180
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 3.12.0 < 5.4.3005.4.300
linuxlinux_kernel>= 5.11.0 < 5.15.1945.15.194
linuxlinux_kernel>= 5.16.0 < 6.1.1556.1.155
linuxlinux_kernel>= 5.5.0 < 5.10.2455.10.245
linuxlinux_kernel>= 6.13.0 < 6.16.106.16.10
linuxlinux_kernel>= 6.2.0 < 6.6.1096.6.109
linuxlinux_kernel>= 6.7.0 < 6.12.506.12.50
msrcazl3_kernel_6.6.104.2-4_on_azure_linux_3.0

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
osv7.8HIGH
vendor_msrc9.8CRITICAL
vendor_ubuntu7.8HIGH
vendor_redhat7.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.