CVE-2025-39711 is a use-after-free vulnerability in the Linux kernel's media:ivsc driver, specifically affecting the ACE and CSI components. This flaw occurs during system shutdown when missing mei_cldev_disable() calls lead to a freed client memory still being referenced, resulting in a crash. The vulnerability is rated as High severity (CVSS 7.8), indicating that a local attacker with low privileges could achieve high confidentiality, integrity, and availability impacts. There is currently no public exploit code available, and it is not listed on the CISA KEV catalog, though it has garnered moderate community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.6, < 6.6.103CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.12.44CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.13, < 6.16.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure FIPS) vulnerabilities
Mar 4, 2026Linux kernel (Azure) vulnerabilities
Mar 4, 2026Linux kernel (Xilinx) vulnerabilities
Feb 24, 2026Linux kernel (IBM) vulnerabilities
Feb 24, 2026media: ivsc: Fix crash at shutdown due to missing mei_cldev_disable() calls
Sep 9, 2025kernel: media: ivsc: Fix crash at shutdown due to missing mei_cldev_disable() calls
Sep 5, 2025