SB2025120483 - Improper locking in Linux kernel pci driver
Published: December 4, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2025-40219)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the sriov_add_vfs() and sriov_del_vfs() functions in drivers/pci/iov.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/05703271c3cdcc0f2a8cf6ebdc45892b8ca83520
- https://git.kernel.org/stable/c/1e8a80290f964bdbad225221c8a1594c7e01c8fd
- https://git.kernel.org/stable/c/36039348bca77828bf06eae41b8f76e38cd15847
- https://git.kernel.org/stable/c/53154cd40ccf285f1d1c24367824082061d155bd
- https://git.kernel.org/stable/c/5c1cd7d405e94dc6cb320cc0cc092b74895b6ddf
- https://git.kernel.org/stable/c/a24219172456f035d886857e265ca24c85b167c8
- https://git.kernel.org/stable/c/a645ca21de09e3137cbb224fa6c23cca873a1d01
- https://git.kernel.org/stable/c/ee40e5db052d7c6f406fdb95ad639c894c74674c