You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve 2025 38174
About this tag
CVE-2025-38174 is a kernel-level vulnerability in the Linux Thunderbolt driver, described as a double-dequeue issue in the configuration request path. It can cause kernel crashes and general protection faults, potentially taking hosts offline. The vulnerability has been reported on Linux versions around 6.6.65, and Microsoft's Security Response Center has identified Azure Linux as a potentially affected product. This tag covers discussions and analysis of the CVE, its impact on systems, and related security updates.
A kernel-level Thunderbolt bug tracked as CVE‑2025‑38174 — described upstream as "thunderbolt: Do not double dequeue a configuration request" — has been assigned after reports of kernel crashes caused by a double-dequeue operation in the Thunderbolt configuration request path. The immediate...