CVE-2025-39970

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-39970
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-39970.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-39970
Downstream
Related
Published
2025-10-15T07:55:53.610Z
Modified
2025-11-28T02:35:29.349287Z
Summary
i40e: fix input validation logic for action_meta
Details

In the Linux kernel, the following vulnerability has been resolved:

i40e: fix input validation logic for action_meta

Fix condition to check 'greater or equal' to prevent OOB dereference.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/39xxx/CVE-2025-39970.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e284fc280473bed23f2e1ed324e102a48f7d17e1
Fixed
a88c1b2746eccf00e2094b187945f0f1e990b400
Fixed
28465770ca3b694286ff9ed6dfd558413f57d98f
Fixed
f8c8e11825b24661596fa8db2f0981ba17ed0817
Fixed
461e0917eedcd159d87f3ea846754a1e07d7e78a
Fixed
3883e9702b6a4945e93b16c070f338a9f5b496f9
Fixed
3118f41d8fa57b005f53ec3db2ba5eab1d7ba12b
Fixed
560e1683410585fbd5df847f43433c4296f0d222
Fixed
9739d5830497812b0bdeaee356ddefbe60830b88

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.17.0
Fixed
5.4.300
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.245
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.194
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.155
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.109
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.50
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.16.10