# CVE-2025-71064

## Summary

- **CVE ID:** CVE-2025-71064
- **Severity:** UNKNOWN
- **CVSS Score:** 1.01
- **CWE:** N/A
- **Published:** Jan 13, 2026
- **Last Modified:** Sep 17, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

net: hns3: using the num_tqps in the vf driver to apply for resources

Currently, hdev->htqp is allocated using hdev->num_tqps, and kinfo->tqp
is allocated using kinfo->num_tqps. However, kinfo->num_tqps is set to
min(new_tqps, hdev->num_tqps);  Therefore, kinfo->num_tqps may be smaller
than hdev->num_tqps, which causes some hdev->htqp[i] to remain
uninitialized in hclgevf_knic_setup().

Thus, this patch allocates hdev->htqp and kinfo->tqp using hdev->num_tqps,
ensuring that the lengths of hdev->htqp and kinfo->tqp are consistent
and that all elements are properly initialized.

## Affected Products

- Linux — Linux (e2cb1dec9779ba2d89302a653eb0abaeb8682196)
- Linux — Linux (4.16)
- Linux — Linux (0)
- Linux — Linux (5.10.248)
- Linux — Linux (5.15.198)
- Linux — Linux (6.1.160)
- Linux — Linux (6.6.120)
- Linux — Linux (6.12.64)
- Linux — Linux (6.18.3)
- Linux — Linux (6.19)

## References

- [CNA](https://git.kernel.org/stable/c/c149decd8c18ae6acdd7a6041d74507835cf26e6)
- [CNA](https://git.kernel.org/stable/c/bcefdb288eedac96fd2f583298927e9c6c481489)
- [CNA](https://git.kernel.org/stable/c/6cd8a2930df850f4600fe8c57d0662b376520281)
- [CNA](https://git.kernel.org/stable/c/1956d47a03eb625951e9e070db39fe2590e27510)
- [CNA](https://git.kernel.org/stable/c/429f946a7af3fbf08761d218746cd4afa80a7954)
- [CNA](https://git.kernel.org/stable/c/62f28d79a6186a602a9d926a2dbb5b12b6867df7)
- [CNA](https://git.kernel.org/stable/c/c2a16269742e176fccdd0ef9c016a233491a49ad)
- [siemens-SADP](https://cert-portal.siemens.com/productcert/html/ssa-019113.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.21%
- **EPSS Percentile:** 11.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._