Answer in brief
CVE-2025-39972 records a Unknown severity vulnerability in i40e: fix idx validation in i40e_validate_queue_map. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-39972 records a Unknown severity vulnerability in i40e: fix idx validation in i40e_validate_queue_map. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c27eac48160de72dee33d42b5a33cc7b8a2eb1f5 <b6cb93a7ff208f324c7ec581d72995f80e115e0e || >=c27eac48160de72dee33d42b5a33cc7b8a2eb1f5 <6f15a7b34fae75e745bdc2ec05e06ddfd0dd2f3c || >=c27eac48160de72dee33d42b5a33cc7b8a2eb1f5 <34dfac0c904829967d500c51f216916ce1452957 || >=c27eac48160de72dee33d42b5a33cc7b8a2eb1f5 <4d5e804a9e19b639b18fd13664dbad3c03c79e61 || >=c27eac48160de72dee33d42b5a33cc7b8a2eb1f5 <50a1e2f50f6c22b93b94eb8d168a1be3c05bf5cd || >=c27eac48160de72dee33d42b5a33cc7b8a2eb1f5 <cc4191e8ef40d2249c1b9a8617d22ec8a976b574 || >=c27eac48160de72dee33d42b5a33cc7b8a2eb1f5 <d4e3eaaa3cb3af77836d806c89cd6ebf533a7320 || >=c27eac48160de72dee33d42b5a33cc7b8a2eb1f5 <aa68d3c3ac8d1dcec40d52ae27e39f6d32207009 | b6cb93a7ff208f324c7ec581d72995f80e115e0e, 6f15a7b34fae75e745bdc2ec05e06ddfd0dd2f3c, 34dfac0c904829967d500c51f216916ce1452957, 4d5e804a9e19b639b18fd13664dbad3c03c79e61, 50a1e2f50f6c22b93b94eb8d168a1be3c05bf5cd, cc4191e8ef40d2249c1b9a8617d22ec8a976b574, d4e3eaaa3cb3af77836d806c89cd6ebf533a7320, aa68d3c3ac8d1dcec40d52ae27e39f6d32207009 |
| Linux/Linuxgeneric | 4.17 | Not reported |
Published upstream
Oct 15, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: i40e: fix idx validation in i40e_validate_queue_map Ensure idx is within range of active/initialized TCs when iterating over vf->ch[idx] in i40e_validate_queue_map().
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c27eac48160de72dee33d42b5a33cc7b8a2eb1f5 <b6cb93a7ff208f324c7ec581d72995f80e115e0e || >=c27eac48160de72dee33d42b5a33cc7b8a2eb1f5 <6f15a7b34fae75e745bdc2ec05e06ddfd0dd2f3c || >=c27eac48160de72dee33d42b5a33cc7b8a2eb1f5 <34dfac0c904829967d500c51f216916ce1452957 || >=c27eac48160de72dee33d42b5a33cc7b8a2eb1f5 <4d5e804a9e19b639b18fd13664dbad3c03c79e61 || >=c27eac48160de72dee33d42b5a33cc7b8a2eb1f5 <50a1e2f50f6c22b93b94eb8d168a1be3c05bf5cd || >=c27eac48160de72dee33d42b5a33cc7b8a2eb1f5 <cc4191e8ef40d2249c1b9a8617d22ec8a976b574 || >=c27eac48160de72dee33d42b5a33cc7b8a2eb1f5 <d4e3eaaa3cb3af77836d806c89cd6ebf533a7320 || >=c27eac48160de72dee33d42b5a33cc7b8a2eb1f5 <aa68d3c3ac8d1dcec40d52ae27e39f6d32207009 | b6cb93a7ff208f324c7ec581d72995f80e115e0e, 6f15a7b34fae75e745bdc2ec05e06ddfd0dd2f3c, 34dfac0c904829967d500c51f216916ce1452957, 4d5e804a9e19b639b18fd13664dbad3c03c79e61, 50a1e2f50f6c22b93b94eb8d168a1be3c05bf5cd, cc4191e8ef40d2249c1b9a8617d22ec8a976b574, d4e3eaaa3cb3af77836d806c89cd6ebf533a7320, aa68d3c3ac8d1dcec40d52ae27e39f6d32207009 |
| Linux/Linuxgeneric | 4.17 | Not reported |
Published upstream
Oct 15, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: i40e: fix idx validation in i40e_validate_queue_map Ensure idx is within range of active/initialized TCs when iterating over vf->ch[idx] in i40e_validate_queue_map().
Quoted source text, attributed separately from HOL analysis.