{"id":"DEBIAN-CVE-2025-40002","details":"In the Linux kernel, the following vulnerability has been resolved:  thunderbolt: Fix use-after-free in tb_dp_dprx_work  The original code relies on cancel_delayed_work() in tb_dp_dprx_stop(), which does not ensure that the delayed work item tunnel-\u003edprx_work has fully completed if it was already running. This leads to use-after-free scenarios where tb_tunnel is deallocated by tb_tunnel_put(), while tunnel-\u003edprx_work remains active and attempts to dereference tb_tunnel in tb_dp_dprx_work().  A typical race condition is illustrated below:  CPU 0                            | CPU 1 tb_dp_tunnel_active()            |   tb_deactivate_and_free_tunnel()| tb_dp_dprx_start()     tb_tunnel_deactivate()       |   queue_delayed_work()       tb_dp_activate()           |         tb_dp_dprx_stop()        | tb_dp_dprx_work() //delayed worker           cancel_delayed_work()  |     tb_tunnel_put(tunnel);       |                                  |   tunnel = container_of(...); //UAF                                  |   tunnel-\u003e //UAF  Replacing cancel_delayed_work() with cancel_delayed_work_sync() is not feasible as it would introduce a deadlock: both tb_dp_dprx_work() and the cleanup path acquire tb-\u003elock, and cancel_delayed_work_sync() would wait indefinitely for the work item that cannot proceed.  Instead, implement proper reference counting: - If cancel_delayed_work() returns true (work is pending), we release   the reference in the stop function. - If it returns false (work is executing or already completed), the   reference is released in delayed work function itself.  This ensures the tb_tunnel remains valid during work item execution while preventing memory leaks.  This bug was found by static analysis.","modified":"2026-08-27T22:49:00.869038711Z","published":"2025-10-18T08:15:34.243Z","upstream":["CVE-2025-40002"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-40002"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.17.6-1"}]}],"versions":["6.12.100-1","6.12.101-1","6.12.105-1","6.12.38-1","6.12.41-1","6.12.43-1","6.12.43-1~bpo12+1","6.12.48-1","6.12.57-1","6.12.57-1~bpo12+1","6.12.63-1","6.12.63-1~bpo12+1","6.12.69-1","6.12.69-1~bpo12+1","6.12.73-1","6.12.73-1~bpo12+1","6.12.74-1","6.12.74-2","6.12.74-2~bpo12+1","6.12.85-1","6.12.85-1~bpo12+1","6.12.86-1","6.12.86-1~bpo12+1","6.12.88-1","6.12.88-1~bpo12+1","6.12.90-1","6.12.90-1~bpo12+1","6.12.90-2","6.12.90-2~bpo12+1","6.12.94-1","6.12.94-1~bpo12+1","6.12.95-1","6.12.95-1~bpo12+1","6.12.96-1","6.13.10-1~exp1","6.13.11-1~exp1","6.13.2-1~exp1","6.13.3-1~exp1","6.13.4-1~exp1","6.13.5-1~exp1","6.13.6-1~exp1","6.13.7-1~exp1","6.13.8-1~exp1","6.13.9-1~exp1","6.13~rc6-1~exp1","6.13~rc7-1~exp1","6.14.3-1~exp1","6.14.5-1~exp1","6.14.6-1~exp1","6.15-1~exp1","6.15.1-1~exp1","6.15.2-1~exp1","6.15.3-1~exp1","6.15.4-1~exp1","6.15.5-1~exp1","6.15.6-1~exp1","6.15~rc7-1~exp1","6.16-1~exp1","6.16.1-1~exp1","6.16.10-1","6.16.11-1","6.16.12-1","6.16.12-1~bpo13+1","6.16.12-2","6.16.3-1","6.16.3-1~bpo13+1","6.16.5-1","6.16.6-1","6.16.7-1","6.16.8-1","6.16.9-1","6.16~rc7-1~exp1","6.17.2-1~exp1","6.17.5-1~exp1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-40002.json"}}],"schema_version":"1.9.0"}