{"id":"CVE-2025-71064","title":"net: hns3: using the num_tqps in the vf driver to apply for resources","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: using the num_tqps in the vf driver to apply for resources\n\nCurrently, hdev->htqp is allocated using hdev->num_tqps, and kinfo->tqp\nis allocated using kinfo-…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= e2cb1dec9779ba2d89302a653eb0abaeb8682196 < c149decd8c18ae6acdd7a6041d74507835cf26e6","Linux >= e2cb1dec9779ba2d89302a653eb0abaeb8682196 < bcefdb288eedac96fd2f583298927e9c6c481489","Linux >= e2cb1dec9779ba2d89302a653eb0abaeb8682196 < 6cd8a2930df850f4600fe8c57d0662b376520281","Linux >= e2cb1dec9779ba2d89302a653eb0abaeb8682196 < 1956d47a03eb625951e9e070db39fe2590e27510","Linux >= e2cb1dec9779ba2d89302a653eb0abaeb8682196 < 429f946a7af3fbf08761d218746cd4afa80a7954","Linux >= e2cb1dec9779ba2d89302a653eb0abaeb8682196 < 62f28d79a6186a602a9d926a2dbb5b12b6867df7","Linux >= e2cb1dec9779ba2d89302a653eb0abaeb8682196 < c2a16269742e176fccdd0ef9c016a233491a49ad","Linux 4.16"],"published":"2026-01-13","updated":"2026-09-08","sourceUpdated":"2026-09-08T08:43:40.555Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2025-71064","references":[{"url":"https://git.kernel.org/stable/c/c149decd8c18ae6acdd7a6041d74507835cf26e6"},{"url":"https://git.kernel.org/stable/c/bcefdb288eedac96fd2f583298927e9c6c481489"},{"url":"https://git.kernel.org/stable/c/6cd8a2930df850f4600fe8c57d0662b376520281"},{"url":"https://git.kernel.org/stable/c/1956d47a03eb625951e9e070db39fe2590e27510"},{"url":"https://git.kernel.org/stable/c/429f946a7af3fbf08761d218746cd4afa80a7954"},{"url":"https://git.kernel.org/stable/c/62f28d79a6186a602a9d926a2dbb5b12b6867df7"},{"url":"https://git.kernel.org/stable/c/c2a16269742e176fccdd0ef9c016a233491a49ad"}],"tags":["cve.org"],"epss":0.00207,"epssPercentile":0.11105,"ingestedAt":"2026-09-08T15:33:26.995Z","slug":"CVE-2025-71064","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: using the num_tqps in the vf driver to apply for resources\n\nCurrently, hdev->htqp is allocated using hdev->num_tqps, and kinfo->tqp\nis allocated using kinfo->num_tqps. However, kinfo->num_tqps is set to\nmin(new_tqps, hdev->num_tqps);  Therefore, kinfo->num_tqps may be smaller\nthan hdev->num_tqps, which causes some hdev->htqp[i] to remain\nuninitialized in hclgevf_knic_setup().\n\nThus, this patch allocates hdev->htqp and kinfo->tqp using hdev->num_tqps,\nensuring that the lengths of hdev->htqp and kinfo->tqp are consistent\nand that all elements are properly initialized.\n\n## Affected\n\n- `Linux >= e2cb1dec9779ba2d89302a653eb0abaeb8682196 < c149decd8c18ae6acdd7a6041d74507835cf26e6`\n- `Linux >= e2cb1dec9779ba2d89302a653eb0abaeb8682196 < bcefdb288eedac96fd2f583298927e9c6c481489`\n- `Linux >= e2cb1dec9779ba2d89302a653eb0abaeb8682196 < 6cd8a2930df850f4600fe8c57d0662b376520281`\n- `Linux >= e2cb1dec9779ba2d89302a653eb0abaeb8682196 < 1956d47a03eb625951e9e070db39fe2590e27510`\n- `Linux >= e2cb1dec9779ba2d89302a653eb0abaeb8682196 < 429f946a7af3fbf08761d218746cd4afa80a7954`\n- `Linux >= e2cb1dec9779ba2d89302a653eb0abaeb8682196 < 62f28d79a6186a602a9d926a2dbb5b12b6867df7`\n- `Linux >= e2cb1dec9779ba2d89302a653eb0abaeb8682196 < c2a16269742e176fccdd0ef9c016a233491a49ad`\n- `Linux 4.16`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}