CVE-2025-39870
Severity CVSS v4.0:
Pending analysis
Type:
CWE-415
Double Free
Publication date:
23/09/2025
Last modified:
20/01/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
dmaengine: idxd: Fix double free in idxd_setup_wqs()<br />
<br />
The clean up in idxd_setup_wqs() has had a couple bugs because the error<br />
handling is a bit subtle. It&#39;s simpler to just re-write it in a cleaner<br />
way. The issues here are:<br />
<br />
1) If "idxd->max_wqs" is
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.1.140 (including) | 6.1.153 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.6.92 (including) | 6.6.107 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.12.30 (including) | 6.12.48 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.14.8 (including) | 6.15 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.15.1 (including) | 6.16.8 (excluding) |
| cpe:2.3:o:linux:linux_kernel:6.15:-:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.15:rc7:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.17:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.17:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.17:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.17:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/25e6146c2812487a88f619d5ff6efbdcd5b2bc31
- https://git.kernel.org/stable/c/39aaa337449e71a41d4813be0226a722827ba606
- https://git.kernel.org/stable/c/9f0e225635475b2285b966271d5e82cba74295b1
- https://git.kernel.org/stable/c/df82c7901513fd0fc738052a8e6a330d92cc8ec9
- https://git.kernel.org/stable/c/ec5430d090d0b6ace8fefa290fc37e88930017d2
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html



