PT-2025-29003 · Unknown+6 · Hisi Acc Vfio Pci+6
Anubis
·
Published
2025-05-10
·
Updated
2026-04-20
·
CVE-2025-38283
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
The Linux kernel contains a flaw within the
hisi acc vfio pci component related to live migration. Specifically, if a Virtual Function (VF) device driver is not loaded in the Guest OS, attempting to migrate device data can result in a null address. Subsequent recovery operations on the destination side will then attempt to access this null address, leading to access errors. The issue is resolved by preventing device data migration during live migration of VMs lacking VF device drivers and by avoiding device queue recovery processing when the destination queue address data is empty.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu
Hisi Acc Vfio Pci