#VU115983 NULL pointer dereference in Linux kernel - CVE-2025-39853
Published: September 22, 2025
Vulnerability identifier: #VU115983
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-39853
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Linux kernel
Linux kernel
Software vendor:
Linux Foundation
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the i40e_client_add_instance() function in drivers/net/ethernet/intel/i40e/i40e_client.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's repository.
External links
- https://git.kernel.org/stable/c/1eadabcf5623f1237a539b16586b4ed8ac8dffcd
- https://git.kernel.org/stable/c/3c6fb929afa313d9d11f780451d113f73922fe5d
- https://git.kernel.org/stable/c/66e7cdbda74ee823ec2bf7b830ebd235c54f5ddf
- https://git.kernel.org/stable/c/971feafe157afac443027acdc235badc6838560b
- https://git.kernel.org/stable/c/9c21fc4cebd44dd21016c61261a683af390343f8
- https://git.kernel.org/stable/c/a556f06338e1d5a85af0e32ecb46e365547f92b9
- https://git.kernel.org/stable/c/e2a5e74879f9b494bbd66fa93f355feacde450c7
- https://git.kernel.org/stable/c/fb216d980fae6561c7c70af8ef826faf059c6515