In the Linux kernel, the following vulnerability has been resolved:
accel/ivpu: Prevent recovery work from being queued during device removal
Use disable_work_sync() instead of cancel_work_sync() in ivpu_dev_fini()
to ensure that no new recovery work items can be queued after device
removal has started. Previously, recovery work could be scheduled even
after canceling existing work, potentially leading to use-after-free
bugs if recovery accessed freed resources.
Rename ivpu_pm_cancel_recovery() to ivpu_pm_disable_recovery() to better
reflect its new behavior.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-10-01 08:15
Updated : 2026-01-14 20:16
NVD link : CVE-2025-39896
Mitre link : CVE-2025-39896
CVE.ORG link : CVE-2025-39896
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-416
Use After Free
