CVE-2025-40166 — Improper Control of a Resource Through its Lifetime in Linux
Severity
3.2LOWOSV
No vectorEPSS
0.0%
top 94.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 12
Latest updateApr 9
Description
In the Linux kernel, the following vulnerability has been resolved:
drm/xe/guc: Check GuC running state before deregistering exec queue
In normal operation, a registered exec queue is disabled and
deregistered through the GuC, and freed only after the GuC confirms
completion. However, if the driver is forced to unbind while the exec
queue is still running, the user may call exec_destroy() after the GuC
has already been stopped and CT communication disabled.
In this case, the driver cannot rec…
Affected Packages5 packages
▶CVEListV5linux/linuxdd08ebf6c3525a7ea2186e636df064ea47281987 — 2c6e5904c5bdbac8e0eadee40f70c42bb83f6dc6+3