Executive brief
A vulnerability in the Linux kernel's DMA engine driver for Intel Data Streaming Accelerator (IDXD) devices could allow a local user to cause a system crash or potentially execute unauthorized code. The issue occurs during the removal of the driver module, where memory is improperly freed twice, leading to system instability. This affects systems using specific Intel acceleration hardware and certain industrial controllers from Siemens.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel's dmaengine idxd driver. The root cause is an improper call to idxd_free() within the idxd_remove() function, which triggers a duplicate put_device() call. This results in a reference count underflow and subsequent use-after-free when the device is unregistered. An attacker with local access could exploit this during module unloading to cause a kernel panic (DoS) or potentially achieve privilege escalation through memory corruption. The vulnerability has been addressed by removing the redundant idxd_free() call in the driver's initialization code.
Affected products
- Linux Linux Kernel 6.1.x, 6.6.x, 6.10.x, 6.11.x
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6 and later
Timeline
- 2025-07-29: disclosed: Initial patch submitted by Intel
- 2025-09-19: patched: Patch committed to stable trees
- 2025-09-23: advisory: CVE-2025-39871 published
References
- https://git.kernel.org/stable/c/0e95ee7f532b21206fe3f1c4054002b0d21e3b9c
- https://git.kernel.org/stable/c/24414bbcb37e1af95190af36c21ae51d497e1a9e
- https://git.kernel.org/stable/c/da4fbc1488a4cec6748da685181ee4449a878dac
- https://git.kernel.org/stable/c/dd7a7e43269711d757fc260b0bbdf7138f75de11
- https://git.kernel.org/stable/c/f41c538881eec4dcf5961a242097d447f848cda6
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html