Junglewise Threat Intelligence

CVE-2025-39966: Linux Kernel use-after-free in iommufd file descriptor abort

CVE-2025-39966 · Severity: high · CVSS 7.8 · Published 2025-10-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's IOMMU file descriptor management could allow a local attacker to crash the system or potentially execute unauthorized code. The issue occurs when the system fails to properly clean up internal data structures during a failed operation, leading to a 'use-after-free' condition. This affects the iommufd component, which is responsible for managing memory access for hardware devices.

Technical details

A use-after-free (UAF) vulnerability exists in the Linux kernel iommufd component due to improper synchronization between file descriptor release and object destruction. When an iommufd_object allocation aborts, the code calls fput(), which schedules an asynchronous release via a workqueue. If the object is immediately freed with kfree() before the workqueue executes, the subsequent release operation attempts to access the freed memory to decrement a reference count. This race condition is triggered during failed object installations. The fix involves using __fput_sync() to ensure synchronous cleanup before the object is destroyed.

Affected products

  • Linux Linux Kernel 6.11, 6.12.50

Timeline

  • 2025-09-29: patched: Initial patch by Jason Gunthorpe
  • 2025-10-15: disclosed: CVE-2025-39966 published

References

Related threats