#VU119815 Improper validation of integrity check value in PCI Express (PCIe) Base Specification - CVE-2025-9612
Published: December 10, 2025
PCI Express (PCIe) Base Specification
PCI-SIG
Description
The vulnerability allows an attacker to bypass implemented security restrictions.
The vulnerability exists due to an error in the PCIe IDE protocol’s Transaction Layer Packet (TLP) ordering enforcement mechanism as described in PCI Express (PCIe) Base Specification. A local user or attacker with physical access to the system can perform a Man-in-the-Middle (MITM) attack to observe and reorder IDE protected TLPs without triggering detection at the receiver and violate integrity objectives that both IDE and TDISP are designed to uphold.