Database/Kernel, userspace & hypervisor
Linux kernel (drivers/pci/pcie): AER's rate limiter dereferences per-device error state without checking it exists.
Impact
AER's rate limiter dereferences per-device error state without checking it exists. When firmware reports an error against a device that has no AER capability, that state is NULL and the node panics inside the error-handling worker - the machine dies while processing an error report rather than logging it.
Who can reach it
Reached through the ACPI APEI/GHES path: platform firmware reports a hardware error and names a source device that does not advertise an AER capability. The upstream crash names an Intel Sky Lake-E DMI device - i.e. a root-complex-internal device on a mainstream server chipset, so the affected hardware is ordinary datacenter silicon, not embedded. The error events that make this path run come from real PCIe traffic, which on a passthrough node includes a tenant driving its own GPU or NIC into generating errors; the tenant does not choose which device firmware blames, so treat this as device/firmware-driven rather than precisely targetable.
What to do
Update to a kernel carrying the fix (no fixed_in published; stable commits below). Interim: on affected Intel server platforms, check whether firmware-first error handling (GHES) is enabled in BIOS and consider native AER handling instead, and monitor GHES-reported corrected-error rates.
References
Related entries
- Linux kernel (drivers/pci/pcie): The AER subsystem allocates its per-device error-tracking structure without checkingCVE-2025-68309 · Linux kernel (drivers/pci/pcie)Medium
- Linux kernel (drivers/pci/pcie): PCIe bandwidth control dereferences a bridge's subordinate bus pointer withoutCVE-2025-22031 · Linux kernel (drivers/pci/pcie)Medium
- Linux kernel (drivers/pci/pcie): The ASPM link state keeps a raw pointer to function 0 of a multi-function device.CVE-2023-53446 · Linux kernel (drivers/pci/pcie)Medium
- Linux kernel (drivers/pci/pcie): The ASPM link state of a PCIe switch is freed as soon as ANY function on the upstreamCVE-2024-58093 · Linux kernel (drivers/pci/pcie)Medium
- Linux kernel (drivers/iommu/iommufd): A user-supplied page shift of 63 overflows the divisor in the iommufdCVE-2025-40293 · Linux kernel (drivers/iommu/iommufd)Medium
- Linux kernel (drivers/pci/endpoint): Endpoint function sub-groups were created asynchronously by a delayed work itemCVE-2025-71233 · Linux kernel (drivers/pci/endpoint)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.