#VU119817 State Issues in PCI Express (PCIe) Base Specification - CVE-2025-9614
Published: December 10, 2025
PCI Express (PCIe) Base Specification
PCI-SIG
Description
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to insufficient guidance on re-keying and stream flushing during device rebinding a PCIe device to a new Trusted Domain Interface (TDI) as described in PCI Express (PCIe) Base Specification. A local user can violate confidentiality or security objectives, leading to security restrictions bypass.