Junglewise Threat Intelligence

CVE-2025-39853: Linux Kernel i40e invalid memory access in MAC list handling

CVE-2025-39853 · Severity: high · CVSS 7.1 · Published 2025-09-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Intel i40e network driver could allow a local user to cause a system crash or potentially access sensitive memory. This issue occurs when the driver attempts to process network hardware addresses from an empty list, leading to an invalid memory access. This could impact the stability and availability of servers using Intel Ethernet controllers.

Technical details

An out-of-bounds read vulnerability exists in the i40e network driver (specifically in i40e_client.c) due to the use of list_first_entry() on a potentially empty MAC address list. In the Linux kernel, list_first_entry() does not return NULL for empty lists; instead, it returns a pointer to an invalid object derived from the list head. When this pointer is subsequently dereferenced in i40e_client_add_instance(), it results in an invalid memory access. An attacker with local access could exploit this to cause a denial of service (kernel panic) or read sensitive kernel memory. The fix replaces the vulnerable call with list_first_entry_or_null() and adds a proper NULL check.

Affected products

  • Linux Linux Kernel 4.6 to 5.4.299, 5.5 to 5.10.243, 5.11 to 5.15.192, 5.16 to 6.1.151, 6.2 to 6.6.105, 6.7 to 6.12.46, 6.13 to 6.16.6

Timeline

  • 2025-08-27: other: Vulnerability fix authored
  • 2025-09-19: disclosed: CVE published
  • 2025-09-19: patched: Fix merged into stable kernel branches

References

Related threats