PT-2025-46611 · Arm+4 · Gicv4+4

Published

2025-08-21

·

Updated

2026-05-22

·

CVE-2025-40136

CVSS v2.0

3.2

Low

VectorAV:L/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains an issue within the crypto/hisilicon/qm module related to interrupt handling for virtual functions. Specifically, the driver did not register a reserved interrupt for virtual functions, leading to a warning message when releasing the interrupt in systems with GICv4 enabled and virtual function passthrough to virtual machines. The issue involves interrupt vector 3, which is designated as an error interrupt for the physical function and a reserved interrupt for the virtual function. Registering the reserved interrupt for the virtual function and setting the IRQF NO AUTOEN flag resolves the warning.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-16139
CVE-2025-40136
ECHO-42C7-1013-144B
OESA-2026-2417
OESA-2026-2418
SUSE-SU-2026:0447-1
SUSE-SU-2026:0472-1
SUSE-SU-2026:0587-1
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8048-1

Affected Products

Debian
Gicv4
Linuxmint
Linux Kernel
Ubuntu