FlawAtlas
Search the atlas
CVE-2025-39841 Not scored

scsi: lpfc: Fix buffer free/clear order in deferred receive path

In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix buffer free/clear order in deferred receive path Fix a use-after-free window by correcting the buffer release sequence in the deferred receive path. The code freed the RQ buffer first and only then cleared the context pointer under the lock. Concurrent paths (e.g., ABTS and the repost path) also inspect and release the same pointer under the lock, so the old order could lead to double-free/UAF. Note that the repost path already uses the correct pattern: detach the pointer under the lock, then free it after dropping the lock. The deferred path should do the same.

Exploit probability 0.2%
Published September 19, 2025
Required by Not available
Last source change July 15, 2026

02 / AFFECTED SOFTWARE

Affected packages

Linux Kernel
Unknown Unknown

03 / CONNECTIONS

Connected vulnerabilities

related ALSA-2025:18281
related ALSA-2025:18318
related ALSA-2025:19102
related ALSA-2025:19103
related OPENSUSE-SU-2025:20081-1
related SUSE-SU-2025:21040-1
related SUSE-SU-2025:21052-1
related SUSE-SU-2025:21056-1
related SUSE-SU-2025:21064-1
related SUSE-SU-2025:21074-1
related SUSE-SU-2025:21139-1
related SUSE-SU-2025:21179-1
related SUSE-SU-2025:4057-1
related SUSE-SU-2025:4128-1
related SUSE-SU-2025:4132-1
related SUSE-SU-2025:4140-1
related SUSE-SU-2025:4141-1
related SUSE-SU-2025:4189-1
related SUSE-SU-2025:4301-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2025-39841

In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix buffer free/clear order in deferred receive path Fix a use-after-free window by correcting the buffer release sequence in the deferred receive path. The code freed the RQ buffer first and only then cleared the context pointer under the lock. Concurrent paths (e.g., ABTS and the repost path) also inspect and release the same pointer under the lock, so the old order could lead to double-free/UAF. Note that the repost path already uses the correct pattern: detach the pointer under the lock, then free it after dropping the lock. The deferred path should do the same.

View original source

05 / REFERENCES

Further evidence