PT-2025-41369 · Linux+1 · Linux Kernel+1

CVE-2025-39958

·

Publicado

2025-01-01

·

Atualizado

2026-08-30

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel’s IOMMU subsystem for s390 architectures. Specifically, when a PCI device is unexpectedly removed (surprise hotplug), attempts to attach the device to the default domain can fail because the hypervisor no longer recognizes the device handle. This failure triggers a warning within the IOMMU group setting function. The fix allows the process to continue as if the registration was successful, relying on hotplug event handling for cleanup, similar to how devices in an error state are managed. This prevents errors during device removal and ensures proper handling of the situation when the device is fenced by the hypervisor, preventing DMA operations.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2025-39958
ECHO-34B9-8F36-6EEE

Produtos afetados

Debian
Linux Kernel