In the Linux kernel, the following vulnerability has been resolved:
ionic: no double destroy workqueue
There are some FW error handling paths that can cause us to try to destroy the workqueue more than once, so let's be sure we're checking for that.
The case where this popped up was in an AER event where the handlers got called in such a way that ionic_reset_prepare() and thus ionic_dev_teardown() got called twice in a row. The second time through the workqueue was already destroyed, and destroy_workqueue() choked on the bad wq pointer.
We didn't hit this in AER handler testing before because at that time we weren't using a private workqueue. Later we replaced the use of the system workqueue with our own private workqueue but hadn't rerun the AER handler testing since then.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 27, 2026 | Jul 27, 2026 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 29, 2024 |
| Ubuntu | — | Upgrade linux-image-realtimeUpgrade linux-image-oem-24.04aUpgrade linux-image-6.11.0-21-generic-64kUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-azureUpgrade linux-image-6.11.0-1012-azureUpgrade linux-image-realtime-hwe-24.04Upgrade linux-image-lowlatency-64k-hwe-24.04Upgrade linux-image-azure-fdeUpgrade linux-image-6.11.0-1011-gcp-64kUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-oracle-64kUpgrade linux-image-gcpUpgrade linux-image-awsUpgrade linux-image-6.11.0-1013-oracle-64kUpgrade linux-image-6.11.0-1010-raspiUpgrade linux-image-virtualUpgrade linux-image-oracleUpgrade linux-image-6.11.0-1011-lowlatency-64kUpgrade linux-image-oem-24.04bUpgrade linux-image-generic-64kUpgrade linux-image-6.11.0-1013-oracleUpgrade linux-image-lowlatency-64kUpgrade linux-image-genericUpgrade linux-image-lowlatencyUpgrade linux-image-6.11.0-1017-oemUpgrade linux-image-raspiUpgrade linux-image-oem-24.04Upgrade linux-image-6.11.0-1011-awsUpgrade linux-image-6.11.0-1007-realtimeUpgrade linux-image-gcp-64kUpgrade linux-image-lowlatency-hwe-24.04Upgrade linux-image-6.11.0-1012-azure-fdeUpgrade linux-image-6.11.0-21-genericUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-6.11.0-1011-gcpUpgrade linux-image-6.11.0-1011-lowlatency | Mar 28, 2025 | Dec 29, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub