including PCI(-X) bridges, a lookup of the upstream bridge is required.
This lookup, itself involving acquiring of a lock, is done in a context
where acquiring that lock is unsafe. This can lead to a deadlock.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Avoiding the passing through of the affected device types will avoid the vulnerability.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6068-1 | xen security update |
EUVD |
EUVD-2025-21765 | When setting up interrupt remapping for legacy PCI(-X) devices, including PCI(-X) bridges, a lookup of the upstream bridge is required. This lookup, itself involving acquiring of a lock, is done in a context where acquiring that lock is unsafe. This can lead to a deadlock. |
Tue, 13 Jan 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:o:xen:xen:*:*:*:*:*:*:x86:* |
Wed, 23 Jul 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xen
Xen xen |
|
| Vendors & Products |
Xen
Xen xen |
Thu, 17 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-833 | |
| Metrics |
cvssV3_1
|
Thu, 17 Jul 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 17 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When setting up interrupt remapping for legacy PCI(-X) devices, including PCI(-X) bridges, a lookup of the upstream bridge is required. This lookup, itself involving acquiring of a lock, is done in a context where acquiring that lock is unsafe. This can lead to a deadlock. | |
| Title | deadlock potential with VT-d and legacy PCI device pass-through | |
| References |
|
Status: PUBLISHED
Assigner: XEN
Published:
Updated: 2025-07-17T14:21:42.020Z
Reserved: 2025-02-26T09:04:42.837Z
Link: CVE-2025-1713
Updated: 2025-07-17T14:04:25.770Z
Status : Analyzed
Published: 2025-07-17T14:15:30.527
Modified: 2026-01-13T22:16:10.213
Link: CVE-2025-1713
No data.
OpenCVE Enrichment
Updated: 2025-07-23T20:19:26Z
Debian DSA
EUVD