cbcvebase.
CVE-2025-40219
published 2025-12-04

CVE-2025-40219: In the Linux kernel, the following vulnerability has been resolved: PCI/IOV: Fix race between SR-IOV enable/disable and hotplug Commit 05703271c3cd ("PCI/IOV…

PriorityP420high7.8
EPSS
0.22%
12.4th percentile
In the Linux kernel, the following vulnerability has been resolved: PCI/IOV: Fix race between SR-IOV enable/disable and hotplug Commit 05703271c3cd ("PCI/IOV: Add PCI rescan-remove locking when enabling/disabling SR-IOV") tried to fix a race between the VF removal inside sriov_del_vfs() and concurrent hot unplug by taking the PCI rescan/remove lock in sriov_del_vfs(). Similarly the PCI rescan/remove lock was also taken in sriov_add_vfs() to protect addition of VFs. This approach however causes deadlock on trying to remove PFs with SR-IOV enabled because PFs disable SR-IOV during removal and this removal happens under the PCI rescan/remove lock. So the original fix had to be reverted. Instead of taking the PCI rescan/remove lock in sriov_add_vfs() and sriov_del_vfs(), fix the race that occurs with SR-IOV enable and disable vs hotplug higher up in the callchain by taking the lock in sriov_numvfs_store() before calling into the driver's sriov_configure() callback.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.6-1 (forky)linux 6.19.6-1 (forky)
linuxlinux
linuxlinux>= 18f9e9d150fccfa747875df6f0a9f606740762b3 < 3cddde484471c602bea04e6f384819d336a1ff843cddde484471c602bea04e6f384819d336a1ff84
linuxlinux>= 18f9e9d150fccfa747875df6f0a9f606740762b3 < d7673ac466eca37ec3e6b7cc9ccdb06de3304e9bd7673ac466eca37ec3e6b7cc9ccdb06de3304e9b
linuxlinux>= 18f9e9d150fccfa747875df6f0a9f606740762b3 < 7c37920c96b85ef4255a7acc795e99e63dd38d597c37920c96b85ef4255a7acc795e99e63dd38d59
linuxlinux>= 18f9e9d150fccfa747875df6f0a9f606740762b3 < 1047ca2d816994f31e1475e63e0c0b78255997471047ca2d816994f31e1475e63e0c0b7825599747
linuxlinux>= 18f9e9d150fccfa747875df6f0a9f606740762b3 < 97c18f074ff1c12d016a0753072a3afdfa0b961197c18f074ff1c12d016a0753072a3afdfa0b9611
linuxlinux>= 18f9e9d150fccfa747875df6f0a9f606740762b3 < bea1d373098b22d7142da48750ce5526096425bcbea1d373098b22d7142da48750ce5526096425bc
linuxlinux>= 18f9e9d150fccfa747875df6f0a9f606740762b3 < f3015627b6e9ddf85cfeaf42405b3c194dde2c36f3015627b6e9ddf85cfeaf42405b3c194dde2c36
linuxlinux>= 18f9e9d150fccfa747875df6f0a9f606740762b3 < a5338e365c4559d7b4d7356116b0eb95b12e08d5a5338e365c4559d7b4d7356116b0eb95b12e08d5
linuxlinux_kernel>= 0 < 6.19.6-16.19.6-1
linuxlinux_kernel>= 0 < 5.15.0-170.1805.15.0-170.180
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 5.0.0 < 5.4.3015.4.301
linuxlinux_kernel>= 5.11.0 < 5.15.1955.15.195
linuxlinux_kernel>= 5.16.0 < 6.1.1576.1.157
linuxlinux_kernel>= 5.5.0 < 5.10.2465.10.246
linuxlinux_kernel>= 6.13.0 < 6.17.46.17.4
linuxlinux_kernel>= 6.2.0 < 6.6.1136.6.113
linuxlinux_kernel>= 6.7.0 < 6.12.546.12.54
msrcazl3_kernel_6.6.112.1-2_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-azure-5.15
ubuntulinux-intel-iotg-5.15

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc5.5MEDIUM
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.