CVE-2025-71064

UnknownEPSS 0.17%

Last modified

CVE-2025-71064 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: net: hns3: using the num_tqps in the vf driver to apply for resources Currently, hdev->htqp is allocated using hdev->num_tqps, and kinfo->tqp is allocated using kinfo->num_tqps. However, kinfo->num_tqps is set to min(new_tqps, hdev->num_tqps); Therefore, kinfo->num_tqps may be smaller than hdev->num_tqps, which causes some hdev->htqp[i] to remain uninitialized in hclgevf_knic_setup(). Thus, this patch allocates hdev->htqp and kinfo->tqp using hdev->num_tqps, ensuring that the lengths of hdev->htqp and kinfo->tqp are consistent and that all elements are properly initialized.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: net: hns3: using the num_tqps in the vf driver to apply for resources Currently, hdev->htqp is allocated using hdev->num_tqps, and kinfo->tqp is allocated using kinfo->num_tqps. However, kinfo->num_tqps is set to min(new_tqps, hdev->num_tqps); Therefore, kinfo->num_tqps may be smaller than hdev->num_tqps, which causes some hdev->htqp[i] to remain uninitialized in hclgevf_knic_setup(). Thus, this patch allocates hdev->htqp and kinfo->tqp using hdev->num_tqps, ensuring that the lengths of hdev->htqp and kinfo->tqp are consistent and that all elements are properly initialized.

Metrics

EPSS Probability
0.17%

6.9th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= e2cb1dec9779ba2d89302a653eb0abaeb8682196, < c149decd8c18ae6acdd7a6041d74507835cf26e6; >= e2cb1dec9779ba2d89302a653eb0abaeb8682196, < bcefdb288eedac96fd2f583298927e9c6c481489; >= e2cb1dec9779ba2d89302a653eb0abaeb8682196, < 6cd8a2930df850f4600fe8c57d0662b376520281; >= e2cb1dec9779ba2d89302a653eb0abaeb8682196, < 1956d47a03eb625951e9e070db39fe2590e27510; >= e2cb1dec9779ba2d89302a653eb0abaeb8682196, < 429f946a7af3fbf08761d218746cd4afa80a7954; >= e2cb1dec9779ba2d89302a653eb0abaeb8682196, < 62f28d79a6186a602a9d926a2dbb5b12b6867df7; >= e2cb1dec9779ba2d89302a653eb0abaeb8682196, < c2a16269742e176fccdd0ef9c016a233491a49ad
LinuxLinux4.16

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2025-71064?
In the Linux kernel, the following vulnerability has been resolved: net: hns3: using the num_tqps in the vf driver to apply for resources Currently, hdev->htqp is allocated using hdev->num_tqps, and kinfo->tqp is allocated using kinfo->num_tqps. However, kinfo->num_tqps is set to min(new_tqps, hdev->num_tqps); Therefore, kinfo->num_tqps may be smaller than hdev->num_tqps, which causes some hdev->htqp[i] to remain uninitialized in hclgevf_knic_setup(). Thus, this patch allocates hdev->htqp and kinfo->tqp using hdev->num_tqps, ensuring that the lengths of hdev->htqp and kinfo->tqp are consistent and that all elements are properly initialized.
How severe is CVE-2025-71064?
Severity scoring for CVE-2025-71064 is pending analysis. The EPSS model estimates a 0.17% probability of exploitation in the next 30 days.
How do I fix CVE-2025-71064?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2025

Are you affected by CVE-2025-71064?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST