Data Integrity and Confidentiality Issue in PCI Express Products by PCI-SIG
CVE-2025-9613

Currently unrated

What is CVE-2025-9613?

A vulnerability in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification reveals concerns over insufficient guidance related to tag reuse after completion timeouts. This oversight may lead to multiple outstanding Non-Posted Requests utilizing the same tag, creating a tag aliasing situation. Such conditions can jeopardize the correct delivery of completions to appropriate security contexts, posing risks to both data integrity and confidentiality.

Affected Version(s)

PCI Express Integrity and Data Encryption (PCIe IDE) Specification 0 < 7.1-Rev7.0

PCI Express Integrity and Data Encryption (PCIe IDE) Specification 0 < 6.5-Rev7.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-9613 : Data Integrity and Confidentiality Issue in PCI Express Products by PCI-SIG