PT-2025-36315 · Unknown+8 · Qat 4Xxx.Ko+8
Published
2025-01-01
·
Updated
2026-04-20
·
CVE-2025-39721
CVSS v2.0
6.0
Medium
| Vector | AV:L/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A use-after-free scenario can occur in the Linux kernel's crypto QAT (Quality of Acceleration Technology) subsystem. Repeatedly loading and unloading a device-specific QAT driver (e.g.,
qat 4xxx.ko) in a tight loop can lead to a kernel crash. This happens when a power management interrupt is triggered just before the device-specific driver is unloaded, while the core driver (intel qat.ko) remains loaded. The shared workqueue (qat misc wq) used by the drivers can cause a deferred routine from the device-specific driver to execute after the driver is unloaded, resulting in a dereference of freed memory and a kernel crash.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu
Intel Qat.Ko
Qat 4Xxx.Ko