State Issues in PCI Express (PCIe) Base Specification - CVE-2025-9614
Published: December 10, 2025
PCI Express (PCIe) Base Specification
Detailed vulnerability description
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to insufficient guidance on re-keying and stream flushing during device rebinding a PCIe device to a new Trusted Domain Interface (TDI) as described in PCI Express (PCIe) Base Specification. A local user can violate confidentiality or security objectives, leading to security restrictions bypass.