cbcvebase.
CVE-2025-40023
published 2025-10-24

CVE-2025-40023: In the Linux kernel, the following vulnerability has been resolved: drm/xe/vf: Don't expose sysfs attributes not applicable for VFs VFs can't read…

PriorityP421high7.5
EPSS
0.17%
6.8th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/xe/vf: Don't expose sysfs attributes not applicable for VFs VFs can't read BMG_PCIE_CAP(0x138340) register nor access PCODE (already guarded by the info.skip_pcode flag) so we shouldn't expose attributes that require any of them to avoid errors like: [] xe 0000:03:00.1: [drm] Tile0: GT0: VF is trying to read an \ inaccessible register 0x138340+0x0 [] RIP: 0010:xe_gt_sriov_vf_read32+0x6c2/0x9a0 [xe] [] Call Trace: [] xe_mmio_read32+0x110/0x280 [xe] [] auto_link_downgrade_capable_show+0x2e/0x70 [xe] [] dev_attr_show+0x1a/0x70 [] sysfs_kf_seq_show+0xaa/0x120 [] kernfs_seq_show+0x41/0x60 (cherry picked from commit a2d6223d224f333f705ed8495bf8bebfbc585c35)

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.16.10-1 (forky)linux 6.16.10-1 (forky)
linuxlinux
linuxlinux>= 0e414bf7ad012e55c8a0aa4e91f68cb1cf5801ff < bacbadedbba737da8ae6e0464bc0971c30cda4cbbacbadedbba737da8ae6e0464bc0971c30cda4cb
linuxlinux>= 0e414bf7ad012e55c8a0aa4e91f68cb1cf5801ff < 500dad428e5b0de4c1bdfa893822a6e06ddad0b5500dad428e5b0de4c1bdfa893822a6e06ddad0b5
linuxlinux_kernel>= 0 < 6.16.10-16.16.10-1
linuxlinux_kernel>= 6.16.0 < 6.16.106.16.10
msrcazl3_rust_1.75.0-14_on_azure_linux_3.0
msrcazl3_rust_1.86.0-1_on_azure_linux_3.0
msrccbl2_python-mako_1.2.2-1_on_cbl_mariner_2.0
msrccm1_python-mako_1.0.7-5_on_cbl_mariner_1.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.