CVE-2025-39853: i40e: Fix potential invalid access when MAC list is empty
Published Sep 19, 2025
·Updated
i40e: Fix potential invalid access when MAC list is empty
Affected Software
16 affected componentsFixes available
Linux Linux kernel
Microsoft azl3 kernel 6.6.96.2-2
Linux Linux kernel>=4.6<5.4.299
Linux Linux kernel>=5.5<5.10.243
Linux Linux kernel>=5.11<5.15.192
Linux Linux kernel>=5.16<6.1.151
Linux Linux kernel>=6.2<6.6.105
Linux Linux kernel>=6.7<6.12.46
Linux Linux kernel>=6.13<6.16.6
Linux Linux kernel=6.17-rc1
Linux Linux kernel=6.17-rc2
Linux Linux kernel=6.17-rc3
Linux Linux kernel=6.17-rc4
Debian Debian Linux=11.0
Microsoft azl3 kernel 6.6.104.2-4
Microsoft cbl2 kernel 5.15.186.1-1
Remediation
Event History
Sep 19, 2025
CVE Published
via MITRE·03:26 PM
Data Sourced
via MITRE·03:26 PM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 21, 2025
Data Sourced
via Microsoft·01:01 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:01 AM
Affected Software
Updated
via Microsoft·08:01 AM
DescriptionSeverity
Updated
via Microsoft·08:01 AM
SeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-39853?
CVE-2025-39853 is classified as a potential security vulnerability due to invalid memory access risk.
2
How do I fix CVE-2025-39853?
To fix CVE-2025-39853, update your Linux kernel to the latest stable version where the vulnerability is patched.
3
What types of systems are affected by CVE-2025-39853?
CVE-2025-39853 affects systems running the Linux kernel, particularly those utilizing the i40e driver.
4
Can CVE-2025-39853 be exploited?
Yes, CVE-2025-39853 can potentially be exploited due to invalid access, leading to system instability or crashes.
5
When was CVE-2025-39853 disclosed?
CVE-2025-39853 was disclosed following updates to the Linux kernel addressing the issue.