-

CVE-2025-39898

In the Linux kernel, the following vulnerability has been resolved:

e1000e: fix heap overflow in e1000_set_eeprom

Fix a possible heap overflow in e1000_set_eeprom function by adding
input validation for the requested length of the change in the EEPROM.
In addition, change the variable type from int to size_t for better
code practices and rearrange declarations to RCT.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLinux
Product Linux
Default Statusunaffected
Version < ea832ec0583e2398ea0c5ed8d902c923e16f53c4
Version bc7f75fa97884d41efbfde1397b621fefb2550b4
Status affected
Version < ce8829d3d44b8622741bccca9f4408bc3da30b2b
Version bc7f75fa97884d41efbfde1397b621fefb2550b4
Status affected
Version < 99a8772611e2d7ec318be7f0f072037914a1f509
Version bc7f75fa97884d41efbfde1397b621fefb2550b4
Status affected
Version < b48adcacc34fbbc49046a7ee8a97839bef369c85
Version bc7f75fa97884d41efbfde1397b621fefb2550b4
Status affected
Version < 50a84d5c814039ad2abe2748aec3e89324a548a7
Version bc7f75fa97884d41efbfde1397b621fefb2550b4
Status affected
Version < b370f7b1f470a8d5485cc1e40e8ff663bb55d712
Version bc7f75fa97884d41efbfde1397b621fefb2550b4
Status affected
Version < 0aec3211283482cfcdd606d1345e1f9acbcabd31
Version bc7f75fa97884d41efbfde1397b621fefb2550b4
Status affected
Version < 90fb7db49c6dbac961c6b8ebfd741141ffbc8545
Version bc7f75fa97884d41efbfde1397b621fefb2550b4
Status affected
VendorLinux
Product Linux
Default Statusaffected
Version 2.6.24
Status affected
Version < 2.6.24
Version 0
Status unaffected
Version <= 5.4.*
Version 5.4.299
Status unaffected
Version <= 5.10.*
Version 5.10.243
Status unaffected
Version <= 5.15.*
Version 5.15.192
Status unaffected
Version <= 6.1.*
Version 6.1.151
Status unaffected
Version <= 6.6.*
Version 6.6.105
Status unaffected
Version <= 6.12.*
Version 6.12.46
Status unaffected
Version <= 6.16.*
Version 6.16.6
Status unaffected
Version <= *
Version 6.17
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.116
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string