CVE-2025-38624: PCI: pnv_php: Clean up allocated IRQs on unplug

Published Aug 22, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

PCI: pnvphp: Clean up allocated IRQs on unplug

When the root of a nested PCIe bridge configuration is unplugged, the pnvphp driver leaked the allocated IRQ resources for the child bridges' hotplug event notifications, resulting in a panic.

Fix this by walking all child buses and deallocating all its IRQ resources before calling pcihpremovedevices().

Also modify the lifetime of the workqueue at struct pnvphpslot::wq so that it is only destroyed in pnvphpfreeslot(), instead of pnvphpdisableirq(). This is required since pnvphpdisableirq() will now be called by workers triggered by hot unplug interrupts, so the workqueue needs to stay allocated.

The abridged kernel panic that occurs without this patch is as follows:

WARNING: CPU: 0 PID: 687 at kernel/irq/msi.c:292 msidevicedatarelease+0x6c/0x9c CPU: 0 UID: 0 PID: 687 Comm: bash Not tainted 6.14.0-rc5+ #2 Call Trace: msidevicedatarelease+0x34/0x9c (unreliable) releasenodes+0x64/0x13c devresreleaseall+0xc0/0x140 devicedel+0x2d4/0x46c pcidestroydev+0x5c/0x194 pcihpremovedevices+0x90/0x128 pcihpremovedevices+0x44/0x128 pnvphpdisableslot+0x54/0xd4 powerwritefile+0xf8/0x18c pcislotattrstore+0x40/0x5c sysfskfwrite+0x64/0x78 kernfsfopwriteiter+0x1b0/0x290 vfswrite+0x3bc/0x50c ksyswrite+0x84/0x140 systemcallexception+0x124/0x230 systemcallvectoredcommon+0x15c/0x2ec

[bhelgaas: tidy comments]

Affected Software

12 affected componentsFixes available
linux_kernel>6.14.0-rc5
Linux Linux kernel>=4.9<5.10.241
Linux Linux kernel>=5.11<5.15.190
Linux Linux kernel>=5.16<6.1.148
Linux Linux kernel>=6.2<6.6.102
Linux Linux kernel>=6.7<6.12.42
Linux Linux kernel>=6.13<6.15.10
Linux Linux kernel>=6.16<6.16.1
Debian Debian Linux=11.0
Microsoft cbl2 kernel 5.15.186.1-1
Microsoft azl3 kernel 6.6.96.2-2
Microsoft azl3 kernel 6.6.96.2-1

Event History

Aug 22, 2025
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityAffected Software
Sep 3, 2025
Data Sourced
via Microsoft·11:05 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·11:05 PM
Affected Software
Updated
via Microsoft·11:05 PM
Affected Software
Updated
via Microsoft·11:05 PM
SeverityAffected Software
Updated
via Microsoft·11:05 PM
DescriptionSeverity

Frequently Asked Questions

1

What is the severity of CVE-2025-38624?

CVE-2025-38624 has a medium severity rating due to potential resource leaks affecting system stability.

2

How do I fix CVE-2025-38624?

To fix CVE-2025-38624, update the Linux kernel to the latest version where this vulnerability has been patched.

3

Which systems are affected by CVE-2025-38624?

CVE-2025-38624 affects the Linux kernel, particularly systems using the pnv_php driver for nested PCIe bridges.

4

What impact does CVE-2025-38624 have on system performance?

CVE-2025-38624 can lead to performance degradation as it may cause resource leakage upon unplugging PCIe components.

5

Is there a workaround for CVE-2025-38624?

Currently, there is no documented workaround for CVE-2025-38624 other than applying the kernel update.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203