CVE-2025-39870 is a double free vulnerability (CWE-415) in the Linux kernel's dmaengine idxd driver, specifically within the idxd_setup_wqs() function, affecting Debian Linux distributions. This flaw can lead to high impact on confidentiality, integrity, and availability. With a CVSS score of 7.8 (High), it requires local access and low privileges to exploit, but does not involve user interaction. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.1.140, < 6.1.153CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.6.92, < 6.6.107CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.12.30, < 6.12.48CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.14.8, < 6.15CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.15.1, < 6.16.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Xilinx) vulnerabilities
May 7, 2026Linux kernel (Azure FIPS) vulnerabilities
Apr 9, 2026Linux kernel (Raspberry Pi) vulnerabilities
Apr 1, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (AWS) vulnerabilities
Mar 23, 2026Linux kernel (Real-time) vulnerabilities
Mar 17, 2026Linux kernel (FIPS) vulnerabilities
Mar 16, 2026Linux kernel (NVIDIA) vulnerabilities
Mar 16, 2026Linux kernel vulnerabilities
Mar 16, 2026kernel: dmaengine: idxd: Fix double free in idxd_setup_wqs()
Sep 23, 2025