CVE-2025-61554
BaseFortify
Publication date: 2025-10-16
Last updated on: 2025-10-21
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| bitvisor | bitvisor | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-369 | The product divides a value by zero. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a divide-by-zero error in the VirtIO network device emulation within BitVisor. It occurs in versions from commit 108df6 (2020-05-20) to commit 480907 (2025-07-06). A local attacker can exploit this by crafting a specific PCI configuration space access, which triggers the divide-by-zero and causes the host hypervisor to crash.
How can this vulnerability impact me? :
The vulnerability can cause a denial of service by crashing the host hypervisor. This means that an attacker with local access could disrupt the operation of the virtualized environment, potentially leading to downtime or loss of availability of services running on the hypervisor.