Junglewise Threat Intelligence

CVE-2025-39706: Linux Kernel NULL pointer dereference in amdkfd debugfs cleanup

CVE-2025-39706 · Severity: medium · CVSS 5.5 · Published 2025-09-05

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's AMD GPU driver could allow a local user to cause a system crash. The issue occurs during specific cleanup operations where the system attempts to access memory that has already been cleared. This results in a kernel hang, leading to a complete denial of service for the affected machine.

Technical details

A NULL pointer dereference exists in the drm/amdkfd driver due to an incorrect teardown sequence in the kfd_exit function. When the KFD debugfs is destroyed (kfd_debugfs_fini) before the KFD workqueue (kfd_process_destroy_wq), the workqueue may attempt to call kfd_debugfs_remove_process. This function tries to recursively remove entries under /sys/kernel/debug/kfd/proc/<pid> using a dentry that has already been freed, causing the kernel to hang. The fix reorders the cleanup sequence to ensure the workqueue is destroyed before the debugfs infrastructure is finalized. This is reachable by local users with sufficient privileges to trigger module unloading or process cleanup involving the AMD KFD driver.

Affected products

  • Linux Linux Kernel 3.19 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.44, 6.13 to 6.16.4

Timeline

  • 2025-09-05: advisory: Initial NVD publication
  • 2025-08-06: patched: Fix committed to mainline kernel

References

Related threats