CVE-2025-38200

MEDIUM

Linux Kernel - Integer Underflow in i40e_clear_hw MMIO Write Access

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: i40e: fix MMIO write access to an invalid page in i40e_clear_hw When the device sends a specific input, an integer underflow can occur, leading to MMIO write access to an invalid page. Prevent the integer underflow by changing the type of related variables.

Scores

CVSS v3 5.5
EPSS 0.0016
EPSS Percentile 5.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-191
Status published
Products (27)
debian/debian_linux 11.0
linux/Kernel 3.12.0 - 5.4.295linux
linux/Kernel 5.11.0 - 5.15.186linux
linux/Kernel 5.16.0 - 6.1.142linux
linux/Kernel 5.5.0 - 5.10.239linux
linux/Kernel 6.13.0 - 6.15.4linux
linux/Kernel 6.2.0 - 6.6.95linux
linux/Kernel 6.7.0 - 6.12.35linux
Linux/Linux < 3.12
Linux/Linux 1bff652941c4d94f97610c9a30473aad6f5b2fff - 015bac5daca978448f2671478c553ce1f300c21e
... and 17 more
Published Jul 04, 2025
Tracked Since Feb 18, 2026