PT-2025-46611 · Arm+4 · Gicv4+4

Publicado

2025-08-21

·

Atualizado

2026-05-22

·

CVE-2025-40136

CVSS v2.0

3.2

Baixa

VetorAV:L/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains an issue within the crypto/hisilicon/qm module related to interrupt handling for virtual functions. Specifically, the driver did not register a reserved interrupt for virtual functions, leading to a warning message when releasing the interrupt in systems with GICv4 enabled and virtual function passthrough to virtual machines. The issue involves interrupt vector 3, which is designated as an error interrupt for the physical function and a reserved interrupt for the virtual function. Registering the reserved interrupt for the virtual function and setting the IRQF NO AUTOEN flag resolves the warning.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-16139
CVE-2025-40136
ECHO-42C7-1013-144B
OESA-2026-2417
OESA-2026-2418
SUSE-SU-2026:0447-1
SUSE-SU-2026:0472-1
SUSE-SU-2026:0587-1
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8048-1

Produtos afetados

Debian
Gicv4
Linuxmint
Linux Kernel
Ubuntu