CVE-2025-39896

I

n the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Prevent recovery work from being queued during device removal Use disable_work_sync() instead of cancel_work_sync() in ivpu_dev_fini() to ensure that no new recovery work items can be queued after device removal has started. Previously, recovery work could be scheduled even after canceling existing work, potentially leading to use-after-free bugs if recovery accessed freed resources. Rename ivpu_pm_cancel_recovery() to ivpu_pm_disable_recovery() to better reflect its new behavior.

Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.17:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.17:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.17:rc4:*:*:*:*:*:*

History

12 Dec 2025, 18:44

Type Values Removed Values Added
CWE CWE-416
CPE cpe:2.3:o:linux:linux_kernel:6.17:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.17:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.17:rc4:*:*:*:*:*:*
References () https://git.kernel.org/stable/c/54c49eca38dbd06913a696f6d7610937dcfad226 - () https://git.kernel.org/stable/c/54c49eca38dbd06913a696f6d7610937dcfad226 - Patch
References () https://git.kernel.org/stable/c/565d2c15b6c36c3250e694f7b9a86229c1787be5 - () https://git.kernel.org/stable/c/565d2c15b6c36c3250e694f7b9a86229c1787be5 - Patch
References () https://git.kernel.org/stable/c/69a79ada8eb034ce016b5b78fb7d08d8687223de - () https://git.kernel.org/stable/c/69a79ada8eb034ce016b5b78fb7d08d8687223de - Patch
First Time Linux linux Kernel
Linux
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

02 Oct 2025, 19:12

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-01 08:15

Updated : 2026-01-14 20:16


NVD link : CVE-2025-39896

Mitre link : CVE-2025-39896

CVE.ORG link : CVE-2025-39896


JSON object : View

Products Affected
CWE
CWE-416

Use After Free