{"id":"DEBIAN-CVE-2025-21713","details":"In the Linux kernel, the following vulnerability has been resolved:  powerpc/pseries/iommu: Don't unset window if it was never set  On pSeries, when user attempts to use the same vfio container used by different iommu group, the spapr_tce_set_window() returns -EPERM and the subsequent cleanup leads to the below crash.     Kernel attempted to read user page (308) - exploit attempt?    BUG: Kernel NULL pointer dereference on read at 0x00000308    Faulting instruction address: 0xc0000000001ce358    Oops: Kernel access of bad area, sig: 11 [#1]    NIP:  c0000000001ce358 LR: c0000000001ce05c CTR: c00000000005add0    \u003csnip\u003e    NIP [c0000000001ce358] spapr_tce_unset_window+0x3b8/0x510    LR [c0000000001ce05c] spapr_tce_unset_window+0xbc/0x510    Call Trace:      spapr_tce_unset_window+0xbc/0x510 (unreliable)      tce_iommu_attach_group+0x24c/0x340 [vfio_iommu_spapr_tce]      vfio_container_attach_group+0xec/0x240 [vfio]      vfio_group_fops_unl_ioctl+0x548/0xb00 [vfio]      sys_ioctl+0x754/0x1580      system_call_exception+0x13c/0x330      system_call_vectored_common+0x15c/0x2ec    \u003csnip\u003e    --- interrupt: 3000  Fix this by having null check for the tbl passed to the spapr_tce_unset_window().","modified":"2026-08-27T23:05:19.757075422Z","published":"2025-02-27T02:15:14.960Z","upstream":["CVE-2025-21713"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-21713"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.13-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-21713.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.13-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-21713.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}