Junglewise Threat Intelligence

CVE-2025-39721: Linux Kernel Intel QAT use-after-free in device shutdown

CVE-2025-39721 · Severity: medium · CVSS 5.5 · Published 2025-09-05

Technologies: Linux Kernel, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP. Vendors: Linux, Siemens.

Executive brief

A vulnerability in the Linux kernel's Intel QuickAssist Technology (QAT) driver can cause a system crash during hardware driver maintenance. If the driver is repeatedly loaded and unloaded, a background task may attempt to access memory that has already been cleared, leading to a kernel failure. This primarily impacts system availability and stability in environments using Intel QAT hardware acceleration.

Technical details

A use-after-free vulnerability exists in the Linux kernel's Intel QAT (QuickAssist Technology) driver due to improper synchronization during device shutdown. The driver utilizes a shared workqueue (qat_misc_wq) owned by the core driver (intel_qat.ko). If a power management interrupt triggers a deferred routine just before a device-specific driver (e.g., qat_4xxx.ko) is unloaded, that routine may remain pending in the queue. When the routine eventually executes, it dereferences memory that was freed during the driver unload process, resulting in a page fault and kernel crash. The fix involves flushing the misc workqueue during device shutdown to ensure all pending tasks are completed before memory is released.

Affected products

  • Linux Linux Kernel e5745f34113b to 3d4df408ba9b
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6

Timeline

  • 2025-09-05: advisory: Initial publication of CVE-2025-39721
  • 2025-07-18: patched: Fix committed to Linux stable tree

References

Related threats