CVE-2025-40001
Last modified
CVE-2025-40001 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: scsi: mvsas: Fix use-after-free bugs in mvs_work_queue During the detaching of Marvell's SAS/SATA controller, the original code calls cancel_delayed_work() in mvs_free() to cancel the delayed work item mwq->work_q. However, if mwq->work_q is already running, the cancel_delayed_work() may fail to cancel it. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: scsi: mvsas: Fix use-after-free bugs in mvs_work_queue During the detaching of Marvell's SAS/SATA controller, the original code calls cancel_delayed_work() in mvs_free() to cancel the delayed work item mwq->work_q. However, if mwq->work_q is already running, the cancel_delayed_work() may fail to cancel it. This can lead to use-after-free scenarios where mvs_free() frees the mvs_info while mvs_work_queue() is still executing and attempts to access the already-freed mvs_info. A typical race condition is illustrated below: CPU 0 (remove) | CPU 1 (delayed work callback) mvs_pci_remove() | mvs_free() | mvs_work_queue() cancel_delayed_work() | kfree(mvi) | | mvi-> // UAF Replace cancel_delayed_work() with cancel_delayed_work_sync() to ensure that the delayed work item is properly canceled and any executing delayed work item completes before the mvs_info is deallocated. This bug was found by static analysis.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 20b09c2992fefbe78f8cede7b404fb143a413c52, < a6f68f219d4d4b92d7c781708d4afc4cc42961ec; >= 20b09c2992fefbe78f8cede7b404fb143a413c52, < aacd1777d4a795c387a20b9ca776e2c1225d05d7; >= 20b09c2992fefbe78f8cede7b404fb143a413c52, < 6ba7e73cafd155a5d3abf560d315f0bab2b9d89f; >= 20b09c2992fefbe78f8cede7b404fb143a413c52, < c2c35cb2a31844f84f21ab364b38b4309d756d42; >= 20b09c2992fefbe78f8cede7b404fb143a413c52, < 3c90f583d679c81a5a607a6ae0051251b6dee35b; >= 20b09c2992fefbe78f8cede7b404fb143a413c52, < 00d3af40b158ebf7c7db2b3bbb1598a54bf28127; >= 20b09c2992fefbe78f8cede7b404fb143a413c52, < feb946d2fc9dc754bf3d594d42cd228860ff8647; >= 20b09c2992fefbe78f8cede7b404fb143a413c52, < 60cd16a3b7439ccb699d0bf533799eeb894fd217 |
| Linux | Linux | 2.6.31 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-40001?
How severe is CVE-2025-40001?
How do I fix CVE-2025-40001?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-39996In the Linux kernel, the following vulnerability has been re…
- CVE-2025-39997In the Linux kernel, the following vulnerability has been re…
- CVE-2025-39998In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2025-39999In the Linux kernel, the following vulnerability has been re…
- CVE-2025-4000A vulnerability, which was classified as problematic, was fo…5.4
- CVE-2025-40000In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2025-40002In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40003In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40004In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40005In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-40006In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40007In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2025-40001?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
