CVE-2025-38283

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/07/2025
Last modified:
19/11/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> hisi_acc_vfio_pci: bugfix live migration function without VF device driver<br /> <br /> If the VF device driver is not loaded in the Guest OS and we attempt to<br /> perform device data migration, the address of the migrated data will<br /> be NULL.<br /> The live migration recovery operation on the destination side will<br /> access a null address value, which will cause access errors.<br /> <br /> Therefore, live migration of VMs without added VF device drivers<br /> does not require device data migration.<br /> In addition, when the queue address data obtained by the destination<br /> is empty, device queue recovery processing will not be performed.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.18 (including) 6.6.94 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.34 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.15.3 (excluding)