CVE-2025-39896

In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Prevent recovery work from being queued during device removal Use disable_work_sync() instead of cancel_work_sync() in ivpu_dev_fini() to ensure that no new recovery work items can be queued after device removal has started. Previously, recovery work could be scheduled even after canceling existing work, potentially leading to use-after-free bugs if recovery accessed freed resources. Rename ivpu_pm_cancel_recovery() to ivpu_pm_disable_recovery() to better reflect its new behavior.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.17:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.17:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.17:rc4:*:*:*:*:*:*

History

12 Dec 2025, 18:44

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/54c49eca38dbd06913a696f6d7610937dcfad226 - () https://git.kernel.org/stable/c/54c49eca38dbd06913a696f6d7610937dcfad226 - Patch
References () https://git.kernel.org/stable/c/565d2c15b6c36c3250e694f7b9a86229c1787be5 - () https://git.kernel.org/stable/c/565d2c15b6c36c3250e694f7b9a86229c1787be5 - Patch
References () https://git.kernel.org/stable/c/69a79ada8eb034ce016b5b78fb7d08d8687223de - () https://git.kernel.org/stable/c/69a79ada8eb034ce016b5b78fb7d08d8687223de - Patch
First Time Linux
Linux linux Kernel
CPE cpe:2.3:o:linux:linux_kernel:6.17:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.17:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.17:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:*
CWE CWE-416
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

01 Oct 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-01 08:15

Updated : 2025-12-12 18:44


NVD link : CVE-2025-39896

Mitre link : CVE-2025-39896

CVE.ORG link : CVE-2025-39896


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-416

Use After Free