Back

MEDIUM

ACPI: video: Fix use-after-free in acpi_video_switch_brightness()

Published Nov 21, 2025

Description

The switch_brightness_work delayed work accesses device->brightness and device->backlight, freed by acpi_video_dev_unregister_backlight() during device removal.

If the work executes after acpi_video_bus_unregister_backlight() frees these resources, it causes a use-after-free when acpi_video_switch_brightness() dereferences device->brightness or device->backlight.

Fix this by calling cancel_delayed_work_sync() for each device's switch_brightness_work in acpi_video_bus_remove_notify_handler() after removing the notify handler that queues the work. This ensures the work completes before the memory is freed.

[ rjw: Changelog edit ]

Affected products

Remediation

Red Hat statement

A use after free occurred in acpi_video_switch_brightness() because delayed work (switch_brightness_work) could run after its associated device->brightness or device->backlight fields were freed during ACPI video device removal. This bug is locally triggerable (privileged or kernel-context only) and mainly leads to kernel crashes (DoS). It demonstrates a race condition between workqueue cleanup and device teardown.

Metrics

Weaknesses (1)

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Nov 21, 2025
Updated Jun 16, 2026
Reserved Apr 16, 2025
CISA Vulnrichment
Updated Jun 16, 2026
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 21, 2025