
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-21913 is a vulnerability discovered in the Linux kernel, specifically affecting the x86/amd_nb component. The issue was disclosed on April 1, 2025, and involves the handling of MSR (Model Specific Register) access in AMD systems running under Xen virtualization (NVD).
The vulnerability stems from the fact that Xen doesn't offer MSRFAM10HMMIOCONFBASE to all guests, which results in unchecked MSR access errors when attempting to read from address 0xc0010058. This specifically occurs in the amdgetmmconfig_range() function, which is called during the PNP device initialization process (NVD).
The vulnerability affects systems running Linux kernel under Xen virtualization, particularly impacting AMD systems. While the immediate impact appears to be warning messages and potential system instability, the full security implications are still being assessed (NVD).
The vulnerability has been addressed in Linux kernel version 6.1.133-1 for Debian's stable distribution (bookworm). The fix involves using rdmsrsafe() in amdgetmmconfigrange() function to properly handle cases where the MSR access is not available (Debian Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."