CVE-2025-39971
In the Linux kernel, the following vulnerability has been resolved: i40e: fix idx validation in config queues msg Ensure idx is within range of active/initialized TCs when iterating over vf->ch[idx] in i40e_vc_config_queues_msg().
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.14%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: i40e: fix idx validation in config queues msg Ensure idx is within range of active/initialized TCs when iterating over vf->ch[idx] in i40e_vc_config_queues_msg().
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 0.14% probability · 4th percentile
- CISA KEV
- Not listed
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/1fa0aadade34481c567cdf4a897c0d4e4d548bd1
- https://git.kernel.org/stable/c/2cc26dac0518d2fa9b67ec813ee60e183480f98a
- https://git.kernel.org/stable/c/5c1f96123113e0bdc6d8dc2b0830184c93da9f65
- https://git.kernel.org/stable/c/8b9c7719b0987b1c6c5fc910599f3618a558dbde
- https://git.kernel.org/stable/c/a6ff2af78343eceb0f77ab1a2fe802183bc21648
- https://git.kernel.org/stable/c/bfcc1dff429d4b99ba03e40ddacc68ea4be2b32b
- https://git.kernel.org/stable/c/f1ad24c5abe1eaef69158bac1405a74b3c365115
- https://git.kernel.org/stable/c/f5f91d164af22e7147130ef8bebbdb28d8ecc6e2
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.