Upstream information

CVE-2025-39896 at MITRE

Description

In the Linux kernel, the following vulnerability has been resolved:

accel/ivpu: Prevent recovery work from being queued during device removal

Use disable_work_sync() instead of cancel_work_sync() in ivpu_dev_fini()
to ensure that no new recovery work items can be queued after device
removal has started. Previously, recovery work could be scheduled even
after canceling existing work, potentially leading to use-after-free
bugs if recovery accessed freed resources.

Rename ivpu_pm_cancel_recovery() to ivpu_pm_disable_recovery() to better
reflect its new behavior.

SUSE information

Overall state of this security issue: Analysis

This issue is currently rated as having not set severity.

SUSE Bugzilla entry: 1250716 [NEW]

No SUSE Security Announcements cross referenced.


SUSE Timeline for this CVE

CVE page created: Wed Oct 1 12:00:16 2025
CVE page last modified: Wed Oct 1 17:40:43 2025