Executive brief
A vulnerability in the Linux kernel's Intel QuickAssist Technology (QAT) driver can cause a system crash during hardware driver maintenance. If the driver is repeatedly loaded and unloaded, a background task may attempt to access memory that has already been cleared, leading to a kernel failure. This primarily impacts system availability and stability in environments using Intel QAT hardware acceleration.
Technical details
A use-after-free vulnerability exists in the Linux kernel's Intel QAT (QuickAssist Technology) driver due to improper synchronization during device shutdown. The driver utilizes a shared workqueue (qat_misc_wq) owned by the core driver (intel_qat.ko). If a power management interrupt triggers a deferred routine just before a device-specific driver (e.g., qat_4xxx.ko) is unloaded, that routine may remain pending in the queue. When the routine eventually executes, it dereferences memory that was freed during the driver unload process, resulting in a page fault and kernel crash. The fix involves flushing the misc workqueue during device shutdown to ensure all pending tasks are completed before memory is released.
Affected products
- Linux Linux Kernel e5745f34113b to 3d4df408ba9b
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6
Timeline
- 2025-09-05: advisory: Initial publication of CVE-2025-39721
- 2025-07-18: patched: Fix committed to Linux stable tree
References
- https://git.kernel.org/stable/c/3d4df408ba9bad2b205c7fb8afc1836a6a4ca88a
- https://git.kernel.org/stable/c/5858448a6c65d8ee3f8600570d3ce19febcb33be
- https://git.kernel.org/stable/c/e59a52e429e13df3feb34f4853a8e36d121ed937
- https://git.kernel.org/stable/c/fa4c14a82747886d333d8baef0d26da86ba1ccf7
- https://git.kernel.org/stable/c/fe546f5c50fc474daca6bee72caa7ab68a74c33d
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html