Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Prevent recovery work from being queued during device removal Use disable_work_sync() instead of cancel_work_sync() in ivpu_dev_fini() to ensure that no new recovery work items can be queued after device removal has started. Previously, recovery work could be scheduled even after canceling existing work, potentially leading to use-after-free bugs if recovery accessed freed resources. Rename ivpu_pm_cancel_recovery() to ivpu_pm_disable_recovery() to better reflect its new behavior.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.8, < 6.12.46 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/54c49eca38dbd06913a696f6d7610937dcfad226Patch
- https://git.kernel.org/stable/c/565d2c15b6c36c3250e694f7b9a86229c1787be5Patch
- https://git.kernel.org/stable/c/69a79ada8eb034ce016b5b78fb7d08d8687223dePatch
FAQ
What is CVE-2025-39896?
CVE-2025-39896 is a vulnerability with a CVSS score of 7.8 (HIGH). In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Prevent recovery work from being queued during device removal Use disable_work_sync() instead of cancel_work_sync() in...
How severe is CVE-2025-39896?
CVE-2025-39896 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-39896?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.