CVE Database
/

CVE-2025-39973

Back to search

CVE-2025-39973

Published: Oct 15, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: i40e: add validation for ring_len param The `ring_len` parameter provided by the virtual function (VF) is assigned directly to the hardware memory context (HMC) without any validation. To address this, introduce an upper boundary check for both Tx and Rx queue lengths. The maximum number of descriptors supported by the hardware is 8k-32. Additionally, enforce alignment constraints: Tx rings must be a multiple of 8, and Rx rings must be a multiple of 32.

VendorProductVersions

Linux

Linux

affected
5c3c48ac6bf56367c4e89f6453cd2d61e50375bd - < 0543d40d6513cdf1c7882811086e59a6455dfe97
affected
5c3c48ac6bf56367c4e89f6453cd2d61e50375bd - < 7d749e38dd2b7e8a80da2ca30c93e09de95bfcf9
affected
5c3c48ac6bf56367c4e89f6453cd2d61e50375bd - < 45a7527cd7da4cdcf3b06b5c0cb1cae30b5a5985
affected
5c3c48ac6bf56367c4e89f6453cd2d61e50375bd - < d3b0d3f8d11fa957171fbb186e53998361a88d4e
affected
5c3c48ac6bf56367c4e89f6453cd2d61e50375bd - < c0c83f4cd074b75cecef107bfc349be7d516c9c4

+3 more versions

Linux

Linux

affected
3.12
unaffected
0 - < 3.12
unaffected
5.4.300 - <= 5.4.*
unaffected
5.10.245 - <= 5.10.*
unaffected
5.15.194 - <= 5.15.*

+5 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now