CVE-2025-39969

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-39969
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-39969.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-39969
Downstream
Related
Published
2025-10-15T07:55:52.948Z
Modified
2025-11-28T02:34:39.428673Z
Summary
i40e: fix validation of VF state in get resources
Details

In the Linux kernel, the following vulnerability has been resolved:

i40e: fix validation of VF state in get resources

VF state I40EVFSTATE_ACTIVE is not the only state in which VF is actually active so it should not be used to determine if a VF is allowed to obtain resources.

Use I40EVFSTATERESOURCESLOADED that is set only in i40evcgetvfresources_msg() and cleared during reset.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/39xxx/CVE-2025-39969.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
171527da84149c2c7aa6a60a64b09d24f3546298
Fixed
185745d56ec958bf8aa773828213237dfcc32f5a
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
eb87117c27e729b0aeef4d72ed40d6a1761b0f68
Fixed
f47876788a23de296c42ef9d505b5c1630f0b4b8
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
2132643b956f553f5abddc9bae20dae267b082e0
Fixed
8e35c80f8570426fe0f0cc92b151ebd835975f22
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
61125b8be85dfbc7e9c7fe1cc6c6d631ab603516
Fixed
6c3981fd59ef11a75005ac9978f034da5a168b6a
Fixed
e748f1ee493f88e38b77363a60499f979d42c58a
Fixed
6128bbc7adc25c87c2f64b5eb66a280b78ef7ab7
Fixed
a991dc56d3e9a2c3db87d0c3f03c24f6595400f1
Fixed
877b7e6ffc23766448236e8732254534c518ba42

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.4.300
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.245
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.194
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.155
Fixed
6.6.109
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.12.50
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.16.10