Answer in brief
CVE-2025-39969 records a Unknown severity vulnerability in i40e: fix validation of VF state in get resources. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-39969 records a Unknown severity vulnerability in i40e: fix validation of VF state in get resources. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=171527da84149c2c7aa6a60a64b09d24f3546298 <185745d56ec958bf8aa773828213237dfcc32f5a || >=eb87117c27e729b0aeef4d72ed40d6a1761b0f68 <f47876788a23de296c42ef9d505b5c1630f0b4b8 || >=2132643b956f553f5abddc9bae20dae267b082e0 <8e35c80f8570426fe0f0cc92b151ebd835975f22 || >=61125b8be85dfbc7e9c7fe1cc6c6d631ab603516 <6c3981fd59ef11a75005ac9978f034da5a168b6a || >=61125b8be85dfbc7e9c7fe1cc6c6d631ab603516 <e748f1ee493f88e38b77363a60499f979d42c58a || >=61125b8be85dfbc7e9c7fe1cc6c6d631ab603516 <6128bbc7adc25c87c2f64b5eb66a280b78ef7ab7 || >=61125b8be85dfbc7e9c7fe1cc6c6d631ab603516 <a991dc56d3e9a2c3db87d0c3f03c24f6595400f1 || >=61125b8be85dfbc7e9c7fe1cc6c6d631ab603516 <877b7e6ffc23766448236e8732254534c518ba42 || >=5.4.165 <5.4.300 || >=5.10.85 <5.10.245 || >=5.15.8 <5.15.194 | 185745d56ec958bf8aa773828213237dfcc32f5a, f47876788a23de296c42ef9d505b5c1630f0b4b8, 8e35c80f8570426fe0f0cc92b151ebd835975f22, 6c3981fd59ef11a75005ac9978f034da5a168b6a, e748f1ee493f88e38b77363a60499f979d42c58a, 6128bbc7adc25c87c2f64b5eb66a280b78ef7ab7, a991dc56d3e9a2c3db87d0c3f03c24f6595400f1, 877b7e6ffc23766448236e8732254534c518ba42, 5.4.300, 5.10.245, 5.15.194 |
| Linux/Linuxgeneric | 5.16 | Not reported |
Published upstream
Oct 15, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: i40e: fix validation of VF state in get resources VF state I40E_VF_STATE_ACTIVE is not the only state in which VF is actually active so it should not be used to determine if a VF is allowed to obtain resources. Use I40E_VF_STATE_RESOURCES_LOADED that is set only in i40e_vc_get_vf_resources_msg() and cleared during reset.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=171527da84149c2c7aa6a60a64b09d24f3546298 <185745d56ec958bf8aa773828213237dfcc32f5a || >=eb87117c27e729b0aeef4d72ed40d6a1761b0f68 <f47876788a23de296c42ef9d505b5c1630f0b4b8 || >=2132643b956f553f5abddc9bae20dae267b082e0 <8e35c80f8570426fe0f0cc92b151ebd835975f22 || >=61125b8be85dfbc7e9c7fe1cc6c6d631ab603516 <6c3981fd59ef11a75005ac9978f034da5a168b6a || >=61125b8be85dfbc7e9c7fe1cc6c6d631ab603516 <e748f1ee493f88e38b77363a60499f979d42c58a || >=61125b8be85dfbc7e9c7fe1cc6c6d631ab603516 <6128bbc7adc25c87c2f64b5eb66a280b78ef7ab7 || >=61125b8be85dfbc7e9c7fe1cc6c6d631ab603516 <a991dc56d3e9a2c3db87d0c3f03c24f6595400f1 || >=61125b8be85dfbc7e9c7fe1cc6c6d631ab603516 <877b7e6ffc23766448236e8732254534c518ba42 || >=5.4.165 <5.4.300 || >=5.10.85 <5.10.245 || >=5.15.8 <5.15.194 | 185745d56ec958bf8aa773828213237dfcc32f5a, f47876788a23de296c42ef9d505b5c1630f0b4b8, 8e35c80f8570426fe0f0cc92b151ebd835975f22, 6c3981fd59ef11a75005ac9978f034da5a168b6a, e748f1ee493f88e38b77363a60499f979d42c58a, 6128bbc7adc25c87c2f64b5eb66a280b78ef7ab7, a991dc56d3e9a2c3db87d0c3f03c24f6595400f1, 877b7e6ffc23766448236e8732254534c518ba42, 5.4.300, 5.10.245, 5.15.194 |
| Linux/Linuxgeneric | 5.16 | Not reported |
Published upstream
Oct 15, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: i40e: fix validation of VF state in get resources VF state I40E_VF_STATE_ACTIVE is not the only state in which VF is actually active so it should not be used to determine if a VF is allowed to obtain resources. Use I40E_VF_STATE_RESOURCES_LOADED that is set only in i40e_vc_get_vf_resources_msg() and cleared during reset.
Quoted source text, attributed separately from HOL analysis.