7.1

CVE-2025-39853

i40e: Fix potential invalid access when MAC list is empty

In the Linux kernel, the following vulnerability has been resolved:

i40e: Fix potential invalid access when MAC list is empty

list_first_entry() never returns NULL - if the list is empty, it still
returns a pointer to an invalid object, leading to potential invalid
memory access when dereferenced.

Fix this by using list_first_entry_or_null instead of list_first_entry.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 4.6 < 5.4.299
Linux ≫ Linux Kernel Version >= 5.5 < 5.10.243
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.192
Linux ≫ Linux Kernel Version >= 5.16 < 6.1.151
Linux ≫ Linux Kernel Version >= 6.2 < 6.6.105
Linux ≫ Linux Kernel Version >= 6.7 < 6.12.46
Linux ≫ Linux Kernel Version >= 6.13 < 6.16.6
Linux ≫ Linux Kernel Version 6.17 Update rc1
Linux ≫ Linux Kernel Version 6.17 Update rc2
Linux ≫ Linux Kernel Version 6.17 Update rc3
Linux ≫ Linux Kernel Version 6.17 Update rc4
Debian ≫ Debian Linux Version 11.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.06
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

https://git.kernel.org/stable/c/971feafe157afac443027acdc235badc6838560b
Patch
https://git.kernel.org/stable/c/3c6fb929afa313d9d11f780451d113f73922fe5d
Patch
https://git.kernel.org/stable/c/1eadabcf5623f1237a539b16586b4ed8ac8dffcd
Patch
https://git.kernel.org/stable/c/e2a5e74879f9b494bbd66fa93f355feacde450c7
Patch
https://git.kernel.org/stable/c/fb216d980fae6561c7c70af8ef826faf059c6515
Patch
https://git.kernel.org/stable/c/66e7cdbda74ee823ec2bf7b830ebd235c54f5ddf
Patch
https://git.kernel.org/stable/c/9c21fc4cebd44dd21016c61261a683af390343f8
Patch
https://git.kernel.org/stable/c/a556f06338e1d5a85af0e32ecb46e365547f92b9
Patch
https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
Third Party Advisory
Mailing List
https://cert-portal.siemens.com/productcert/html/ssa-032379.html
https://cert-portal.siemens.com/productcert/html/ssa-089022.html