boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2025-71112HIGH
Linux Linux — net: hns3: add VLAN id validation before using
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  N  H    7.1   .0013    3.4     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    fe4144d47eef8453459c53a34e9d5940a3e6c219 –  —
  Linux    5.3 –                                       5.10.248
TIMELINE
  Jan 13  Reserved by Linux
  Jan 14  Published (CNA: Linux)
  Jul 30  RESCORED — CVE-2025-71112 (Linux). CVSS 8.8 → 7.1 (NVD).
CWE-125 · CNA: Linux · CVSS v3.1 · 8 references · NVD status: Modified

Description

In the Linux kernel, the following vulnerability has been resolved: net: hns3: add VLAN id validation before using Currently, the VLAN id may be used without validation when receive a VLAN configuration mailbox from VF. The length of vlan_del_fail_bmap is BITS_TO_LONGS(VLAN_N_VID). It may cause out-of-bounds memory access once the VLAN id is bigger than or equal to VLAN_N_VID. Therefore, VLAN id needs to be checked to ensure it is within the range of VLAN_N_VID.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
January 13, 2026ReservedReserved by Linux
January 14, 2026PublishedPublished (CNA: Linux)
July 30, 2026RESCOREDRESCORED — CVE-2025-71112 (Linux). CVSS 8.8 → 7.1 (NVD).

Affected

Affected products and packages — 2 rows
VendorProduct / PackageEcosystemVersion introducedFixed
LinuxLinuxfe4144d47eef8453459c53a34e9d5940a3e6c219
LinuxLinux5.35.10.248

Weaknesses

CWE-125

References (8)

Related

Authoritative record: CVE-2025-71112 at cve.org

Vendors: linux

Weaknesses: CWE-125

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-71112 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.