Home

Description

In the Linux kernel, the following vulnerability has been resolved: i40e: add validation for ring_len param The `ring_len` parameter provided by the virtual function (VF) is assigned directly to the hardware memory context (HMC) without any validation. To address this, introduce an upper boundary check for both Tx and Rx queue lengths. The maximum number of descriptors supported by the hardware is 8k-32. Additionally, enforce alignment constraints: Tx rings must be a multiple of 8, and Rx rings must be a multiple of 32.

PUBLISHED Reserved 2025-04-16 | Published 2025-10-15 | Updated 2025-10-15 | Assigner Linux

Product status

Default status
unaffected

5c3c48ac6bf56367c4e89f6453cd2d61e50375bd before 0543d40d6513cdf1c7882811086e59a6455dfe97
affected

5c3c48ac6bf56367c4e89f6453cd2d61e50375bd before 7d749e38dd2b7e8a80da2ca30c93e09de95bfcf9
affected

5c3c48ac6bf56367c4e89f6453cd2d61e50375bd before 45a7527cd7da4cdcf3b06b5c0cb1cae30b5a5985
affected

5c3c48ac6bf56367c4e89f6453cd2d61e50375bd before d3b0d3f8d11fa957171fbb186e53998361a88d4e
affected

5c3c48ac6bf56367c4e89f6453cd2d61e50375bd before c0c83f4cd074b75cecef107bfc349be7d516c9c4
affected

5c3c48ac6bf56367c4e89f6453cd2d61e50375bd before 05fe81fb9db20464fa532a3835dc8300d68a2f84
affected

5c3c48ac6bf56367c4e89f6453cd2d61e50375bd before afec12adab55d10708179a64d95d650741e60fe0
affected

5c3c48ac6bf56367c4e89f6453cd2d61e50375bd before 55d225670def06b01af2e7a5e0446fbe946289e8
affected

Default status
affected

3.12
affected

Any version before 3.12
unaffected

5.4.300
unaffected

5.10.245
unaffected

5.15.194
unaffected

6.1.155
unaffected

6.6.109
unaffected

6.12.50
unaffected

6.16.10
unaffected

6.17
unaffected

References

git.kernel.org/...c/0543d40d6513cdf1c7882811086e59a6455dfe97

git.kernel.org/...c/7d749e38dd2b7e8a80da2ca30c93e09de95bfcf9

git.kernel.org/...c/45a7527cd7da4cdcf3b06b5c0cb1cae30b5a5985

git.kernel.org/...c/d3b0d3f8d11fa957171fbb186e53998361a88d4e

git.kernel.org/...c/c0c83f4cd074b75cecef107bfc349be7d516c9c4

git.kernel.org/...c/05fe81fb9db20464fa532a3835dc8300d68a2f84

git.kernel.org/...c/afec12adab55d10708179a64d95d650741e60fe0

git.kernel.org/...c/55d225670def06b01af2e7a5e0446fbe946289e8

cve.org (CVE-2025-39973)

nvd.nist.gov (CVE-2025-39973)

Download JSON