In the Linux kernel, the following vulnerability has been resolved:
ACPI: video: Fix use-after-free in acpi_video_switch_brightness()
The switch_brightness_work delayed work accesses device->brightness
and device->backlight, freed by acpi_video_dev_unregister_backlight()
during device removal.
If the work executes after acpi_video_bus_unregister_backlight()
frees these resources, it causes a use-after-free when
acpi_video_switch_brightness() dereferences device->brightness or
device->backlight.
Fix this by calling cancel_delayed_work_sync() for each device's
switch_brightness_work in acpi_video_bus_remove_notify_handler()
after removing the notify handler that queues the work. This ensures
the work completes before the memory is freed.
[ rjw: Changelog edit ]
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2025-11-21 11:15
Updated : 2026-06-17 09:21
NVD link : CVE-2025-40211
Mitre link : CVE-2025-40211
CVE.ORG link : CVE-2025-40211
JSON object : View
Products Affected
No product.
CWE
No CWE.
