CVE-2025-68324

Linux Kernel - Use-After-Free in IMM SCSI Host Adapter Detach

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: imm: Fix use-after-free bug caused by unfinished delayed work The delayed work item 'imm_tq' is initialized in imm_attach() and scheduled via imm_queuecommand() for processing SCSI commands. When the IMM parallel port SCSI host adapter is detached through imm_detach(), the imm_struct device instance is deallocated. However, the delayed work might still be pending or executing when imm_detach() is called, leading to use-after-free bugs when the work function imm_interrupt() accesses the already freed imm_struct memory. The race condition can occur as follows: CPU 0(detach thread) | CPU 1 | imm_queuecommand() | imm_queuecommand_lck() imm_detach() | schedule_delayed_work() kfree(dev) //FREE | imm_interrupt() | dev = container_of(...) //USE dev-> //USE Add disable_delayed_work_sync() in imm_detach() to guarantee proper cancellation of the delayed work item before imm_struct is deallocated.

Scores

EPSS 0.0003
EPSS Percentile 7.9%

Details

Status published
Products (13)
linux/Kernel 2.6.12 - 6.12.63linux
linux/Kernel 6.13.0 - 6.17.13linux
linux/Kernel 6.18.0 - 6.18.2linux
Linux/Linux < 2.6.12
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 31ab2aad7a7b7501e904a09bf361e44671f66092
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 48dd41fa2d6c6a0c50e714deeba06ffe7f91961b
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 9e434426cc23ad5e2aad649327b59aea00294b13
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - ab58153ec64fa3fc9aea09ca09dc9322e0b54a7c
Linux/Linux 2.6.12
Linux/Linux 6.12.63 - 6.12.*
... and 3 more
Published Dec 18, 2025
Tracked Since Feb 18, 2026