CVE-2025-9612 Overview
CVE-2025-9612 affects the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification maintained by PCI-SIG. The specification provides insufficient guidance on Transaction Layer Packet (TLP) ordering and tag uniqueness. This gap allows encrypted PCIe packets to be replayed or reordered without the receiver detecting the manipulation. Local or physical attackers with access to the PCIe bus can violate the integrity guarantees that IDE is designed to enforce. The flaw sits in the specification itself, which means any conformant IDE implementation inherits the weakness until vendors adopt stricter ordering and tag-handling practices.
Critical Impact
An attacker with local or physical access to the PCIe fabric can replay or reorder encrypted TLPs, undermining the confidentiality and integrity assurances IDE is intended to provide for sensitive device-to-device traffic.
Affected Products
- PCI-SIG PCI Express Integrity and Data Encryption (IDE) specification
- Conformant PCIe IDE implementations in CPUs, root complexes, and endpoint devices
- Confidential computing platforms that rely on IDE for TEE-to-device link protection
Discovery Timeline
- 2025-12-09 - CVE-2025-9612 published to the National Vulnerability Database
- 2026-06-17 - Last updated in the NVD database
Technical Details for CVE-2025-9612
Vulnerability Analysis
PCIe IDE provides authenticated encryption for Transaction Layer Packets exchanged across PCIe links. The specification defines cryptographic protections for individual TLPs but does not fully constrain how ordering and tag uniqueness must be enforced across a stream of packets. As a result, a receiver can accept TLPs that are valid in isolation yet have been replayed from an earlier session or delivered out of their original order. This category of weakness falls under broken cryptographic protocol design rather than an implementation bug, so it affects any device that follows the current specification without adding its own mitigations.
Root Cause
The root cause is incomplete protocol specification. IDE encrypts and authenticates each TLP, but the guidance on monotonic counters, nonce reuse boundaries, and tag uniqueness across TLP streams leaves room for ambiguity. Without a strict, specification-mandated sequence validation, replayed and reordered ciphertexts remain cryptographically valid. The vulnerability is tracked under [NVD-CWE-noinfo] and documented by PCI-SIG and CERT.
Attack Vector
Exploitation requires local or physical access to the PCIe bus, consistent with the local attack vector in the CVSS metric. An attacker who can observe and inject traffic on the link, for example through a malicious device, interposer, or a compromised component sharing the fabric, can capture encrypted TLPs and later replay them or reorder in-flight packets. The receiving endpoint accepts the manipulated stream because each TLP still passes IDE authentication. The practical impact is loss of integrity for the protected channel, which is particularly relevant for confidential computing scenarios that extend trust from a CPU TEE to a PCIe device such as a GPU or accelerator.
No verified public exploit code is available. See the PCI-SIG Vulnerabilities Report and CERT Vulnerability Note VU#404544 for the authoritative technical description.
Detection Methods for CVE-2025-9612
Indicators of Compromise
- Unexpected PCIe link renegotiations or IDE session resets on confidential computing hosts
- Appearance of unauthorized or unattested PCIe devices on the fabric, especially interposers between CPU and accelerator
- Device telemetry showing TLP counter or sequence anomalies reported by IDE-aware endpoints
Detection Strategies
- Enable and monitor vendor-provided IDE telemetry that reports replay counter mismatches, out-of-order TLPs, or authentication failures
- Correlate hardware attestation events with workload scheduling to identify devices operating outside expected IDE configurations
- Audit firmware and BMC logs for PCIe topology changes that could indicate physical tampering
Monitoring Recommendations
- Track PCIe device enumeration changes across reboots and alert on new vendor or device IDs in production hosts
- Forward host and hypervisor PCIe error logs into a centralized analytics platform for longitudinal review
- Monitor confidential VM attestation results for failures tied to device link integrity
How to Mitigate CVE-2025-9612
Immediate Actions Required
- Review the PCI-SIG Vulnerabilities Report and inventory all platforms that rely on PCIe IDE for link protection
- Contact CPU, GPU, and accelerator vendors to obtain their guidance and firmware or microcode updates addressing TLP ordering and tag uniqueness
- Restrict physical access to systems running confidential workloads, including interposer and riser slots
Patch Information
This vulnerability resides in the PCIe IDE specification. Remediation requires updated specification guidance from PCI-SIG along with firmware, microcode, or silicon updates from device vendors that enforce strict TLP ordering, monotonic replay counters, and tag uniqueness. Track the PCI-SIG Specifications Overview for revised guidance and consult each hardware vendor for product-specific advisories.
Workarounds
- Limit use of IDE-protected PCIe paths to physically secured hosts within trusted data center zones
- Where supported, enable vendor options that enforce stricter sequence validation or additional replay protection on top of baseline IDE
- Avoid trusting PCIe link integrity alone for confidential computing attestation; validate end-to-end at the application layer where feasible
# Configuration example
# Enumerate PCIe devices and inspect IDE-capable endpoints on a Linux host
lspci -vvv | grep -E 'IDE|Integrity|Encryption'
# Review kernel messages for PCIe AER and link integrity events
dmesg | grep -iE 'pcie|aer|ide'
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.