Junglewise Threat Intelligence

CVE-2025-40219: Linux Kernel race condition in PCI/IOV SR-IOV configuration

CVE-2025-40219 · Severity: info · CVSS 0 · Published 2025-12-04

Technologies: Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A race condition vulnerability was identified in the Linux kernel's PCI subsystem during the enabling or disabling of Single Root I/O Virtualization (SR-IOV). This flaw can lead to system deadlocks or instability when hardware is being added or removed (hotplugged) while virtual functions are being configured. In practice, this could cause a complete system freeze, impacting the availability of servers or industrial controllers using affected hardware.

Technical details

A race condition exists in the Linux kernel's PCI/IOV implementation specifically between SR-IOV enable/disable operations and PCI hotplug events. A previous attempt to fix this by adding locking in sriov_add_vfs() and sriov_del_vfs() resulted in deadlocks during Physical Function (PF) removal because SR-IOV is disabled under the same rescan/remove lock. The vulnerability is addressed by moving the pci_lock_rescan_remove() higher up the callchain into sriov_numvfs_store() before the driver's sriov_configure() callback is executed. This ensures proper synchronization without causing circular dependencies during device removal. An attacker with local administrative privileges could potentially trigger this race to cause a Denial of Service (DoS).

Affected products

  • Linux Linux Kernel v6.12, v6.11, v6.6, v6.1, v5.15, v5.10, v5.4, v4.19
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6

Timeline

  • 2025-12-04: advisory: Initial CVE publication
  • 2025-12-16: patched: Fix committed to Linux kernel stable branches

References

Related threats