Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: vfio/pds: Fix missing detach_ioas op When CONFIG_IOMMUFD is enabled and a device is bound to the pds_vfio_pci driver, the following WARN_ON() trace is seen and probe fails: WARNING: CPU: 0 PID: 5040 at drivers/vfio/vfio_main.c:317 __vfio_register_dev+0x130/0x140 [vfio] <...> pds_vfio_pci 0000:08:00.1: probe with driver pds_vfio_pci failed with error -22 This is because the driver's vfio_device_ops.detach_ioas isn't set. Fix this by using the generic vfio_iommufd_physical_detach_ioas function.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.6, < 6.6.102 |
References
- https://git.kernel.org/stable/c/1df8150ab4cc422bddfbd312d6758c50b688a971Patch
- https://git.kernel.org/stable/c/7dbfae90c5a33f6b694e7068bc9522cc2655373dPatch
- https://git.kernel.org/stable/c/88b962fbd0ac30a65d2869c68d2f145be46ebe4dPatch
- https://git.kernel.org/stable/c/b265dff9fcf047f660976a5c92c83e7c414a2d95Patch
- https://git.kernel.org/stable/c/fe24d5bc635e103a517ec201c3cb571eeab8be2fPatch
FAQ
What is CVE-2025-38625?
CVE-2025-38625 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: vfio/pds: Fix missing detach_ioas op When CONFIG_IOMMUFD is enabled and a device is bound to the pds_vfio_pci driver, the followin...
How severe is CVE-2025-38625?
CVE-2025-38625 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-38625?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.