CVE-2025-39973 affects the Linux kernel’s Intel i40e Ethernet driver: a malicious virtual function can provide an oversized or misaligned ring_len value that is passed to a hardware memory context without adequate validation. The condition can create excessive transmit or receive queue lengths, potentially resulting in memory corruption or undefined behavior. Red Hat rates the issue Moderate with a CVSS v3.1 score of 7.5, while CVE.org assigns 8.8 under different environmental assumptions; RHEL 7 through 10, including applicable real-time kernels, are listed as affected, while RHEL 6 is not affected.
The defect aligns with CWE-131, incorrect calculation of buffer size, a memory-safety weakness that can lead to out-of-bounds access, crashes, sensitive-data exposure, or code execution. Red Hat’s RHSA-2025:21469 provides updated RHEL 9 kernel packages for multiple kernel security issues and requires a reboot after installation; however, Red Hat’s CVE record separately reports no qualifying mitigation for CVE-2025-39973. Organizations should identify systems using affected i40e hardware and virtual-function configurations, apply applicable vendor kernel updates, reboot hosts, and restrict untrusted VF access where operationally possible.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Red Hat last modified its CVE-2025-39973 record. The record listed RHEL 7 through 10 kernel packages as affected, stated RHEL 6 was not affected, and reported no applicable security errata or qualifying mitigation.
Red Hat published Moderate-severity advisory RHSA-2025:21469 with updated Linux kernel packages for RHEL 9 and related variants. The update fixes multiple kernel flaws, including KVM, mount, NFS, kernfs, Bluetooth, i40e, and io_uring vulnerabilities; administrators must reboot after installation.
Red Hat published its record for CVE-2025-39973, a Moderate-severity validation flaw in the Linux kernel Intel i40e driver. A malicious virtual function could provide an oversized or misaligned ring_len value, potentially causing excessive queue lengths, memory corruption, or undefined behavior.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourceaccess.redhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.