CVE-2025-21831
Last modified
CVE-2025-21831 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: PCI: Avoid putting some root ports into D3 on TUXEDO Sirius Gen1 commit 9d26d3a8f1b0 ("PCI: Put PCIe ports into D3 during suspend") sets the policy that all PCIe ports are allowed to use D3. When the system is suspended if the port is not power manageable by the platform and won't be used for wakeup via a PME this sets up the policy for these ports to go into D3hot. This policy generally makes sense from an OSPM perspective but it leads to problems with wakeup from suspend on the TUXEDO Sirius 16 Gen 1 with a specific old BIOS. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: PCI: Avoid putting some root ports into D3 on TUXEDO Sirius Gen1 commit 9d26d3a8f1b0 ("PCI: Put PCIe ports into D3 during suspend") sets the policy that all PCIe ports are allowed to use D3. When the system is suspended if the port is not power manageable by the platform and won't be used for wakeup via a PME this sets up the policy for these ports to go into D3hot. This policy generally makes sense from an OSPM perspective but it leads to problems with wakeup from suspend on the TUXEDO Sirius 16 Gen 1 with a specific old BIOS. This manifests as a system hang. On the affected Device + BIOS combination, add a quirk for the root port of the problematic controller to ensure that these root ports are not put into D3hot at suspend. This patch is based on https://lore.kernel.org/linux-pci/20230708214457.1229-2-mario.limonciello@amd.com but with the added condition both in the documentation and in the code to apply only to the TUXEDO Sirius 16 Gen 1 with a specific old BIOS and only the affected root ports.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.8, < 6.6.78 |
| Linux | Linux Kernel | >= 6.7, < 6.12.14 |
| Linux | Linux Kernel | >= 6.13, < 6.13.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-21831?
How severe is CVE-2025-21831?
How do I fix CVE-2025-21831?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-21826In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-21827In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-21828In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-21829In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-2183An insufficient certificate validation issue in the Palo Alt…5.3
- CVE-2025-21830In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-21832In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-21833In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-21834In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-21835In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-21836In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-21837Rejected reason: This CVE ID has been rejected or withdrawn …
Are you affected by CVE-2025-21831?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
