PT-2025-41369 · Linux+1 · Linux Kernel+1
Published
2025-01-01
·
Updated
2026-04-20
·
CVE-2025-39958
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A flaw exists in the Linux kernel’s IOMMU subsystem for s390 architectures. Specifically, when a PCI device is unexpectedly removed (surprise hotplug), attempts to attach the device to the default domain can fail because the hypervisor no longer recognizes the device handle. This failure triggers a warning within the IOMMU group setting function. The fix allows the process to continue as if the registration was successful, relying on hotplug event handling for cleanup, similar to how devices in an error state are managed. This prevents errors during device removal and ensures proper handling of the situation when the device is fenced by the hypervisor, preventing DMA operations.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Linux Kernel