SB2025092386 - Double free in Linux kernel dma idxd driver
Published: September 23, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Double free (CVE-ID: CVE-2025-39870)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a double free error within the idxd_setup_wqs() function in drivers/dma/idxd/init.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/25e6146c2812487a88f619d5ff6efbdcd5b2bc31
- https://git.kernel.org/stable/c/39aaa337449e71a41d4813be0226a722827ba606
- https://git.kernel.org/stable/c/9f0e225635475b2285b966271d5e82cba74295b1
- https://git.kernel.org/stable/c/df82c7901513fd0fc738052a8e6a330d92cc8ec9
- https://git.kernel.org/stable/c/ec5430d090d0b6ace8fefa290fc37e88930017d2