SB20250704113 - Input validation error in Linux kernel pci hisilicon driver
Published: July 4, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2025-38158)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the vf_qm_func_stop(), vf_qm_check_match(), vf_qm_get_match_data() and vf_qm_read_data() functions in drivers/vfio/pci/hisilicon/hisi_acc_vfio_pci.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/7710c883eb8cb5cf510ca47ec0e26c6cb7e94a4f
- https://git.kernel.org/stable/c/809a9c10274e1bcf6d05f1c0341459a425a4f05f
- https://git.kernel.org/stable/c/884a76e813178778d271fea59783763d32bb7e72
- https://git.kernel.org/stable/c/8bb7170c5a055ea17c6857c256ee73c10ff872eb
- https://git.kernel.org/stable/c/f0423873e7aeb69cb68f4e8fa3827832e7b037ba