Junglewise Threat Intelligence

CVE-2025-39945: Linux Kernel cnic use-after-free in cnic_delete_task

CVE-2025-39945 · Severity: high · CVSS 7.8 · Published 2025-10-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was discovered in the Linux kernel's Broadcom cnic network driver. The issue occurs during the cleanup process when a network device is being removed, where a background task might continue to run after the memory it needs has been deleted. This could lead to a system crash or allow a local attacker to potentially gain unauthorized access or execute malicious code.

Technical details

A use-after-free (UAF) vulnerability exists in the cnic driver (drivers/net/ethernet/broadcom/cnic.c) within the cnic_delete_task function. The root cause is a race condition where cnic_cm_stop_bnx2x_hw() uses cancel_delayed_work() and flush_workqueue(), which fails to guarantee that cyclic delayed work items are fully terminated before cnic_dev is deallocated via cnic_free_dev(). An attacker with local access could exploit this race condition to trigger a UAF when the 'delete_task' callback attempts to dereference the already-freed cnic_dev structure. The fix replaces the asynchronous cancellation with cancel_delayed_work_sync() to ensure all work completes before memory deallocation.

Affected products

  • Linux Linux Kernel fdf24086f475 to fde6e73189f4, 7b6a5b0a6b39, 040505593026, e1fcd4a9c09f, 8eeb2091e72d, 6e33a7eed587, 0627e1481676

Timeline

  • 2025-09-17: patched: Initial patch authored
  • 2025-10-04: advisory: NVD publication date

References

Related threats