cbcvebase.
CVE-2025-71064
published 2026-01-13

CVE-2025-71064: In the Linux kernel, the following vulnerability has been resolved: net: hns3: using the num_tqps in the vf driver to apply for resources Currently, hdev->htqp…

PriorityP420high7.8
EPSS
0.18%
7.4th percentile
In the Linux kernel, the following vulnerability has been resolved: net: hns3: using the num_tqps in the vf driver to apply for resources Currently, hdev->htqp is allocated using hdev->num_tqps, and kinfo->tqp is allocated using kinfo->num_tqps. However, kinfo->num_tqps is set to min(new_tqps, hdev->num_tqps); Therefore, kinfo->num_tqps may be smaller than hdev->num_tqps, which causes some hdev->htqp[i] to remain uninitialized in hclgevf_knic_setup(). Thus, this patch allocates hdev->htqp and kinfo->tqp using hdev->num_tqps, ensuring that the lengths of hdev->htqp and kinfo->tqp are consistent and that all elements are properly initialized.

Affected

51 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= e2cb1dec9779ba2d89302a653eb0abaeb8682196 < c149decd8c18ae6acdd7a6041d74507835cf26e6c149decd8c18ae6acdd7a6041d74507835cf26e6
linuxlinux>= e2cb1dec9779ba2d89302a653eb0abaeb8682196 < bcefdb288eedac96fd2f583298927e9c6c481489bcefdb288eedac96fd2f583298927e9c6c481489
linuxlinux>= e2cb1dec9779ba2d89302a653eb0abaeb8682196 < 6cd8a2930df850f4600fe8c57d0662b3765202816cd8a2930df850f4600fe8c57d0662b376520281
linuxlinux>= e2cb1dec9779ba2d89302a653eb0abaeb8682196 < 1956d47a03eb625951e9e070db39fe2590e275101956d47a03eb625951e9e070db39fe2590e27510
linuxlinux>= e2cb1dec9779ba2d89302a653eb0abaeb8682196 < 429f946a7af3fbf08761d218746cd4afa80a7954429f946a7af3fbf08761d218746cd4afa80a7954
linuxlinux>= e2cb1dec9779ba2d89302a653eb0abaeb8682196 < 62f28d79a6186a602a9d926a2dbb5b12b6867df762f28d79a6186a602a9d926a2dbb5b12b6867df7
linuxlinux>= e2cb1dec9779ba2d89302a653eb0abaeb8682196 < c2a16269742e176fccdd0ef9c016a233491a49adc2a16269742e176fccdd0ef9c016a233491a49ad
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.3-16.18.3-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 4.16.0 < 5.10.2485.10.248
linuxlinux_kernel>= 5.11.0 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13.0 < 6.18.36.18.3
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.12.646.12.64
ubuntulinux-aws
ubuntulinux-aws-6.17
ubuntulinux-aws-fips
ubuntulinux-azure

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.