Security Advisory

CVE-2025-39853

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-09-19 15:26:25
Last updated 2026-05-12 12:07:39
Assigner Linux
State PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: i40e: Fix potential invalid access when MAC list is empty list_first_entry() never returns NULL - if the list is empty, it still returns a pointer to an invalid object, leading to potential invalid memory access when dereferenced. Fix this by using list_first_entry_or_null instead of list_first_entry.