CVE-2025-23161
Published: May 1, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: PCI: vmd: Make vmd_dev::cfg_lock a raw_spinlock_t type The access to the PCI config space via pci_ops::read and pci_ops::write is a low-level hardware access. The functions can be accessed with disabled interrupts even on PREEMPT_RT. The pci_lock is a raw_spinlock_t for this purpose. A spinlock_t becomes a sleeping lock on PREEMPT_RT, so it cannot be acquired with disabled interrupts. The vmd_dev::cfg_lock is accessed in the same context as the pci_lock. Make vmd_dev::cfg_lock a raw_spinlock_t type so it can be used with interrupts disabled. This was reported as: BUG: sleeping function called from invalid context at kernel/locking/spinlock_rt.c:48 Call Trace: rt_spin_lock+0x4e/0x130 vmd_pci_read+0x8d/0x100 [vmd] pci_user_read_config_byte+0x6f/0xe0 pci_read_config+0xfe/0x290 sysfs_kf_bin_read+0x68/0x90 [bigeasy: reword commit message] Tested-off-by: Luis Claudio R. Goncalves <[email protected]> [kwilczynski: commit log] [bhelgaas: add back report info from https://lore.kernel.org/lkml/[email protected]/]
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 185a383ada2e7794b0e82e040223e741b24d2bf8 - < c250262d6485ca333e9821f85b07eb383ec546b1affected 185a383ada2e7794b0e82e040223e741b24d2bf8 - < c2968c812339593ac6e2bdd5cc3adabe3f05fa53affected 185a383ada2e7794b0e82e040223e741b24d2bf8 - < 13e5148f70e81991acbe0bab5b1b50ba699116e7affected 185a383ada2e7794b0e82e040223e741b24d2bf8 - < 5c3cfcf0b4bf43530788b08a8eaf7896ec567484affected 185a383ada2e7794b0e82e040223e741b24d2bf8 - < 2358046ead696ca5c7c628d6c0e2c6792619a3e5+2 more versions |
Linux | Linux | affected 4.5unaffected 0 - < 4.5unaffected 5.15.181 - <= 5.15.*unaffected 6.1.135 - <= 6.1.*unaffected 6.6.88 - <= 6.6.*+4 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now