CVE-2025-1713: deadlock potential with VT-d and legacy PCI device pass-through

Published Feb 27, 2025
·
Updated

When setting up interrupt remapping for legacy PCI(-X) devices, including PCI(-X) bridges, a lookup of the upstream bridge is required. This lookup, itself involving acquiring of a lock, is done in a context where acquiring that lock is unsafe. This can lead to a deadlock.

Affected Software

1 affected component
XEN Xen>=4.0.0

Event History

Jul 17, 2025
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
Description
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-1713?

CVE-2025-1713 has the potential to cause a deadlock, impacting system stability.

2

How do I fix CVE-2025-1713?

To mitigate CVE-2025-1713, it is recommended to update to the latest version of Xen that addresses this vulnerability.

3

What software is affected by CVE-2025-1713?

CVE-2025-1713 affects Xen versions 4.0.0 and newer.

4

What causes the vulnerability in CVE-2025-1713?

The vulnerability in CVE-2025-1713 is caused by improper lock handling during the interrupt remapping setup for legacy PCI devices.

5

Can CVE-2025-1713 lead to data loss?

While CVE-2025-1713 primarily causes deadlocks, it could indirectly contribute to data loss if system stability is compromised.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203