CVE-2025-38200

Source
https://cve.org/CVERecord?id=CVE-2025-38200
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38200.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-38200
Downstream
Related
Published
2025-07-04T13:37:22.076Z
Modified
2026-05-18T05:56:18.832356006Z
Summary
i40e: fix MMIO write access to an invalid page in i40e_clear_hw
Details

In the Linux kernel, the following vulnerability has been resolved:

i40e: fix MMIO write access to an invalid page in i40eclearhw

When the device sends a specific input, an integer underflow can occur, leading to MMIO write access to an invalid page.

Prevent the integer underflow by changing the type of related variables.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38200.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1bff652941c4d94f97610c9a30473aad6f5b2fff
Fixed
872607632c658d3739e4e7889e4f3c419ae2c193
Fixed
5e75c9082987479e647c75ec8fdf18fa68263c42
Fixed
fecb2fc3fc10c95724407cc45ea35af4a65cdde2
Fixed
d88a1e8f024ba26e19350958fecbf771a9960352
Fixed
8cde755f56163281ec2c46b4ae8b61f532758a6f
Fixed
3502dd42f178dae9d54696013386bb52b4f2e655
Fixed
2a1f4f2e36442a9bdf771acf6ee86f3cf876e5ca
Fixed
015bac5daca978448f2671478c553ce1f300c21e

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38200.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.12.0
Fixed
5.4.295
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.239
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.186
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.142
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.95
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.35
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.15.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38200.json"