Database/Kernel, userspace & hypervisor
Linux kernel (drivers/pci/pcie): The ASPM link state of a PCIe switch is freed as soon as ANY function on the upstream
Impact
The ASPM link state of a PCIe switch is freed as soon as ANY function on the upstream port is removed, while downstream ports still hold it as their parent link. Every subsequent reference is a use-after-free, and the reported symptom is a general protection fault that takes the whole node down - all tenants on it, not just the one whose device went away.
Who can reach it
Triggered by device removal under a multi-function PCIe switch upstream port, which is exactly the topology in a GPU box where a Broadcom/PLX switch fans out to eight accelerators or a bank of NVMe. The upstream note says the faults are ESPECIALLY frequent during hot-unplug, because pciehp removes devices on the link bus in reverse order and therefore hits the non-zero function before function 0. No tenant credentials are needed - a surprise removal, a device that drops off the link, or a maintenance pull supplies the event. Requires ASPM enabled and a switch with a multi-function upstream port.
What to do
Update to 5.4.292 / 5.10.236 / 5.15.180 / 6.1.134 / 6.4 / 6.5 or later. Interim: drain the node before any planned PCIe removal under a switch, and consider disabling ASPM (pcie_aspm=off) on nodes where hot-removal under a switch is routine.
References
Related entries
- Linux kernel (drivers/pci/pcie): AER's rate limiter dereferences per-device error state without checking it exists.CVE-2025-40034 · Linux kernel (drivers/pci/pcie)Medium
- Linux kernel (drivers/pci/pcie): The AER subsystem allocates its per-device error-tracking structure without checkingCVE-2025-68309 · Linux kernel (drivers/pci/pcie)Medium
- Linux kernel (drivers/pci/pcie): PCIe bandwidth control dereferences a bridge's subordinate bus pointer withoutCVE-2025-22031 · Linux kernel (drivers/pci/pcie)Medium
- Linux kernel (drivers/pci/pcie): The ASPM link state keeps a raw pointer to function 0 of a multi-function device.CVE-2023-53446 · Linux kernel (drivers/pci/pcie)Medium
- Go FIPS OpenSSL: FIPS-mode zeroed buffers can force HMAC false matches and all-zero derived keysCVE-2024-9355 · Go FIPS OpenSSL backend (golang-fips, zeroed/uninitialised buffer in FIPS mode)Medium
- Linux kernel (drivers/gpu/drm/radeon): The radeon video-encode command-stream parser used an uninitialised stack valueCVE-2025-21996 · Linux kernel (drivers/gpu/drm/radeon)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.