PT-2025-40070 · Linux+2 · Linux Kernel+2

Published

2025-08-08

·

Updated

2026-04-20

·

CVE-2025-39896

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel’s accel/ivpu subsystem where recovery work could be scheduled even after device removal was initiated, potentially leading to use-after-free issues if the recovery process accessed already freed resources. The issue stemmed from using cancel work sync() instead of disable work sync() in the ivpu dev fini() function. The function ivpu pm cancel recovery() was renamed to ivpu pm disable recovery() to accurately reflect its updated functionality.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-15262
CVE-2025-39896
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1

Affected Products

Astra Linux
Linux Kernel
Suse