Database/Kernel, userspace & hypervisor
Linux kernel (drivers/pci/controller): The Hyper-V PCI front-end frees its PCI domain number twice on a probe failure
Impact
The Hyper-V PCI front-end frees its PCI domain number twice on a probe failure - once itself and once again through the bridge release callback. The second free returns an ID that may already have been reissued to a different bus, so two PCI domains can end up carrying the same domain number. Duplicate domain numbering means sysfs paths and device lookups that are supposed to distinguish two hierarchies stop doing so, on the very driver that presents passthrough devices to a guest.
Who can reach it
Guest-side, inside a Linux VM on Hyper-V/Azure that is being given a passthrough device - pci-hyperv is that paravirtual front-end. It requires hv_pci_probe() to fail after the domain number is stored, which is a host- or fabric-side condition (device offer withdrawn, channel setup failing) rather than something guest userspace triggers; a tenant with no control over device offers cannot force it. Nodes not running under Hyper-V never load the driver.
What to do
Boot a kernel where pci-hyperv leaves domain_nr release to the PCI core. Interim: on Hyper-V hosts, watch for the 'ida_free called for id=... which is not allocated' warning as the marker that a domain ID has been double-freed, and restart the affected VM rather than letting it continue with ambiguous domain numbering.
References
Related entries
- Linux kernel (drivers/pci/controller): The Intel VMD driver guarded config-space access with a lock type that becomes aCVE-2025-23161 · Linux kernel (drivers/pci/controller)Medium
- Linux kernel (drivers/iommu/intel): On VT-d scalable mode with VMD enabled, RID2PASID setup fails for devices behindCVE-2022-48916 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/vfio/mdev): If creating an mdev type's sysfs entries partially fails, the parent still registersCVE-2023-52570 · Linux kernel (drivers/vfio/mdev)Medium
- util-linux (wall): WallEscape: escape-sequence injection via wall(1)CVE-2024-28085 · util-linux (wall)Medium
- Linux kernel (drivers/pci/pcie): PCIe bandwidth control dereferences a bridge's subordinate bus pointer withoutCVE-2025-22031 · Linux kernel (drivers/pci/pcie)Medium
- Linux kernel (drivers/pci/endpoint/functions): The NTB endpoint function drivers never checked whether their workqueueCVE-2025-71313 · Linux kernel (drivers/pci/endpoint/functions)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.