CVE-2025-39971

Source
https://cve.org/CVERecord?id=CVE-2025-39971
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-39971.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-39971
Downstream
Related
Published
2025-10-15T07:55:54.270Z
Modified
2026-03-20T12:43:08.081921Z
Summary
i40e: fix idx validation in config queues msg
Details

In the Linux kernel, the following vulnerability has been resolved:

i40e: fix idx validation in config queues msg

Ensure idx is within range of active/initialized TCs when iterating over vf->ch[idx] in i40evcconfigqueuesmsg().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/39xxx/CVE-2025-39971.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c27eac48160de72dee33d42b5a33cc7b8a2eb1f5
Fixed
a6ff2af78343eceb0f77ab1a2fe802183bc21648
Fixed
f5f91d164af22e7147130ef8bebbdb28d8ecc6e2
Fixed
1fa0aadade34481c567cdf4a897c0d4e4d548bd1
Fixed
8b9c7719b0987b1c6c5fc910599f3618a558dbde
Fixed
2cc26dac0518d2fa9b67ec813ee60e183480f98a
Fixed
bfcc1dff429d4b99ba03e40ddacc68ea4be2b32b
Fixed
5c1f96123113e0bdc6d8dc2b0830184c93da9f65
Fixed
f1ad24c5abe1eaef69158bac1405a74b3c365115

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-39971.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.17.0
Fixed
5.4.300
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.245
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.194
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.155
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.109
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.50
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.16.10

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-39971.json"