Answer in brief
CVE-2025-71064 records a Unknown severity vulnerability in net: hns3: using the num_tqps in the vf driver to apply for resources. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=e2cb1dec9779ba2d89302a653eb0abaeb8682196 <c149decd8c18ae6acdd7a6041d74507835cf26e6 || >=e2cb1dec9779ba2d89302a653eb0abaeb8682196 <bcefdb288eedac96fd2f583298927e9c6c481489 || >=e2cb1dec9779ba2d89302a653eb0abaeb8682196 <6cd8a2930df850f4600fe8c57d0662b376520281 || >=e2cb1dec9779ba2d89302a653eb0abaeb8682196 <1956d47a03eb625951e9e070db39fe2590e27510 || >=e2cb1dec9779ba2d89302a653eb0abaeb8682196 <429f946a7af3fbf08761d218746cd4afa80a7954 || >=e2cb1dec9779ba2d89302a653eb0abaeb8682196 <62f28d79a6186a602a9d926a2dbb5b12b6867df7 || >=e2cb1dec9779ba2d89302a653eb0abaeb8682196 <c2a16269742e176fccdd0ef9c016a233491a49ad | c149decd8c18ae6acdd7a6041d74507835cf26e6, bcefdb288eedac96fd2f583298927e9c6c481489, 6cd8a2930df850f4600fe8c57d0662b376520281, 1956d47a03eb625951e9e070db39fe2590e27510, 429f946a7af3fbf08761d218746cd4afa80a7954, 62f28d79a6186a602a9d926a2dbb5b12b6867df7, c2a16269742e176fccdd0ef9c016a233491a49ad |
| Linux/Linuxgeneric | 4.16 | Not reported |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
Published upstream
Jan 13, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 14, 2026
In the Linux kernel, the following vulnerability has been resolved: net: hns3: using the num_tqps in the vf driver to apply for resources Currently, hdev->htqp is allocated using hdev->num_tqps, and kinfo->tqp is allocated using kinfo->num_tqps. However, kinfo->num_tqps is set to min(new_tqps, hdev->num_tqps); Therefore, kinfo->num_tqps may be smaller than hdev->num_tqps, which causes some hdev->htqp[i] to remain uninitialized in hclgevf_knic_setup(). Thus, this patch allocates hdev->htqp and kinfo->tqp using hdev->num_tqps, ensuring that the lengths of hdev->htqp and kinfo->tqp are consistent and that all elements are properly initialized.
Quoted source text, attributed separately from HOL analysis.