CVE-2025-38625
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/08/2025
Last modified:
26/11/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
vfio/pds: Fix missing detach_ioas op<br />
<br />
When CONFIG_IOMMUFD is enabled and a device is bound to the pds_vfio_pci<br />
driver, the following WARN_ON() trace is seen and probe fails:<br />
<br />
WARNING: CPU: 0 PID: 5040 at drivers/vfio/vfio_main.c:317 __vfio_register_dev+0x130/0x140 [vfio]<br />
<br />
pds_vfio_pci 0000:08:00.1: probe with driver pds_vfio_pci failed with error -22<br />
<br />
This is because the driver&#39;s vfio_device_ops.detach_ioas isn&#39;t set.<br />
<br />
Fix this by using the generic vfio_iommufd_physical_detach_ioas<br />
function.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.6 (including) | 6.6.102 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.42 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.15.10 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.16 (including) | 6.16.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/1df8150ab4cc422bddfbd312d6758c50b688a971
- https://git.kernel.org/stable/c/7dbfae90c5a33f6b694e7068bc9522cc2655373d
- https://git.kernel.org/stable/c/88b962fbd0ac30a65d2869c68d2f145be46ebe4d
- https://git.kernel.org/stable/c/b265dff9fcf047f660976a5c92c83e7c414a2d95
- https://git.kernel.org/stable/c/fe24d5bc635e103a517ec201c3cb571eeab8be2f



