{"id":"CVE-2025-39721","title":"crypto: qat - flush misc workqueue during device shutdown","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat - flush misc workqueue during device shutdown\n\nRepeated loading and unloading of a device specific QAT driver, for\nexample qat_4xxx, in a tight loop can lea…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= e5745f34113b758b45d134dec04a7df94dc67131 < fa4c14a82747886d333d8baef0d26da86ba1ccf7","Linux >= e5745f34113b758b45d134dec04a7df94dc67131 < 5858448a6c65d8ee3f8600570d3ce19febcb33be","Linux >= e5745f34113b758b45d134dec04a7df94dc67131 < fe546f5c50fc474daca6bee72caa7ab68a74c33d","Linux >= e5745f34113b758b45d134dec04a7df94dc67131 < e59a52e429e13df3feb34f4853a8e36d121ed937","Linux >= e5745f34113b758b45d134dec04a7df94dc67131 < 3d4df408ba9bad2b205c7fb8afc1836a6a4ca88a","Linux 5.18"],"published":"2025-09-05","updated":"2026-09-08","sourceUpdated":"2026-09-08T08:42:08.901Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2025-39721","references":[{"url":"https://git.kernel.org/stable/c/fa4c14a82747886d333d8baef0d26da86ba1ccf7"},{"url":"https://git.kernel.org/stable/c/5858448a6c65d8ee3f8600570d3ce19febcb33be"},{"url":"https://git.kernel.org/stable/c/fe546f5c50fc474daca6bee72caa7ab68a74c33d"},{"url":"https://git.kernel.org/stable/c/e59a52e429e13df3feb34f4853a8e36d121ed937"},{"url":"https://git.kernel.org/stable/c/3d4df408ba9bad2b205c7fb8afc1836a6a4ca88a"}],"tags":["cve.org"],"epss":0.00143,"epssPercentile":0.03962,"ingestedAt":"2026-09-08T15:33:26.997Z","slug":"CVE-2025-39721","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat - flush misc workqueue during device shutdown\n\nRepeated loading and unloading of a device specific QAT driver, for\nexample qat_4xxx, in a tight loop can lead to a crash due to a\nuse-after-free scenario. This occurs when a power management (PM)\ninterrupt triggers just before the device-specific driver (e.g.,\nqat_4xxx.ko) is unloaded, while the core driver (intel_qat.ko) remains\nloaded.\n\nSince the driver uses a shared workqueue (`qat_misc_wq`) across all\ndevices and owned by intel_qat.ko, a deferred routine from the\ndevice-specific driver may still be pending in the queue. If this\nroutine executes after the driver is unloaded, it can dereference freed\nmemory, resulting in a page fault and kernel crash like the following:\n\n    BUG: unable to handle page fault for address: ffa000002e50a01c\n    #PF: supervisor read access in kernel mode\n    RIP: 0010:pm_bh_handler+0x1d2/0x250 [intel_qat]\n    Call Trace:\n      pm_bh_handler+0x1d2/0x250 [intel_qat]\n      process_one_work+0x171/0x340\n      worker_thread+0x277/0x3a0\n      kthread+0xf0/0x120\n      ret_from_fork+0x2d/0x50\n\nTo prevent this, flush the misc workqueue during device shutdown to\nensure that all pending work items are completed before the driver is\nunloaded.\n\nNote: This approach may slightly increase shutdown latency if the\nworkqueue contains jobs from other devices, but it ensures correctness\nand stability.\n\n## Affected\n\n- `Linux >= e5745f34113b758b45d134dec04a7df94dc67131 < fa4c14a82747886d333d8baef0d26da86ba1ccf7`\n- `Linux >= e5745f34113b758b45d134dec04a7df94dc67131 < 5858448a6c65d8ee3f8600570d3ce19febcb33be`\n- `Linux >= e5745f34113b758b45d134dec04a7df94dc67131 < fe546f5c50fc474daca6bee72caa7ab68a74c33d`\n- `Linux >= e5745f34113b758b45d134dec04a7df94dc67131 < e59a52e429e13df3feb34f4853a8e36d121ed937`\n- `Linux >= e5745f34113b758b45d134dec04a7df94dc67131 < 3d4df408ba9bad2b205c7fb8afc1836a6a4ca88a`\n- `Linux 5.18`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}