CVE-2025-71087
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/01/2026
Last modified:
25/03/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
iavf: fix off-by-one issues in iavf_config_rss_reg()<br />
<br />
There are off-by-one bugs when configuring RSS hash key and lookup<br />
table, causing out-of-bounds reads to memory [1] and out-of-bounds<br />
writes to device registers.<br />
<br />
Before commit 43a3d9ba34c9 ("i40evf: Allow PF driver to configure RSS"),<br />
the loop upper bounds were:<br />
i
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.7.1 (including) | 5.10.248 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.198 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.160 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.120 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.64 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.4 (excluding) |
| cpe:2.3:o:linux:linux_kernel:4.7:-:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.19:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.19:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.19:rc6:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.19:rc7:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.19:rc8:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/18de0e41d69d97fab10b91fecf10ae78a5e43232
- https://git.kernel.org/stable/c/3095228e1320371e143835d0cebeef1a8a754c66
- https://git.kernel.org/stable/c/5bb18bfd505ca1affbca921462c350095a6c798c
- https://git.kernel.org/stable/c/6daa2893f323981c7894c68440823326e93a7d61
- https://git.kernel.org/stable/c/ceb8459df28d22c225a82d74c0f725f2a935d194
- https://git.kernel.org/stable/c/d7369dc8dd7cbf5cee3a22610028d847b6f02982
- https://git.kernel.org/stable/c/f36de3045d006e6d9be1be495f2ed88d1721e752



