PT-2025-43619 · Linux · Linux Kernel

Published

2025-09-22

·

Updated

2025-10-24

·

CVE-2025-40023

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains an issue where sysfs attributes not applicable for Virtual Functions (VFs) are exposed. Specifically, VFs are unable to read the BMG PCIE CAP(0x138340) register or access PCODE, and exposing attributes that require access to these resources can lead to errors. The error message observed includes: 'xe 0000:03:00.1: [drm] Tile0: GT0: VF is trying to read an inaccessible register 0x138340+0x0'. The issue is related to the xe gt sriov vf read32 function and involves reading from memory-mapped I/O (MMIO) using the xe mmio read32 function. The auto link downgrade capable show function is also involved in the call trace.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

BDU:2026-03866
CVE-2025-40023

Affected Products

Linux Kernel