cbcvebase.
CVE-2026-43232
published 2026-05-06

CVE-2026-43232: In the Linux kernel, the following vulnerability has been resolved: net: wan: farsync: Fix use-after-free bugs caused by unfinished tasklets When the FarSync…

PriorityP346high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.39%
31.4th percentile
In the Linux kernel, the following vulnerability has been resolved: net: wan: farsync: Fix use-after-free bugs caused by unfinished tasklets When the FarSync T-series card is being detached, the fst_card_info is deallocated in fst_remove_one(). However, the fst_tx_task or fst_int_task may still be running or pending, leading to use-after-free bugs when the already freed fst_card_info is accessed in fst_process_tx_work_q() or fst_process_int_work_q(). A typical race condition is depicted below: CPU 0 (cleanup) | CPU 1 (tasklet) | fst_start_xmit() fst_remove_one() | tasklet_schedule() unregister_hdlc_device()| | fst_process_tx_work_q() //handler kfree(card) //free | do_bottom_half_tx() | card-> //use The following KASAN trace was captured: BUG: KASAN: slab-use-after-free in do_bottom_half_tx+0xb88/0xd00 Read of size 4 at addr ffff88800aad101c by task ksoftirqd/3/32 ... Call Trace: dump_stack_lvl+0x55/0x70 print_report+0xcb/0x5d0 ? do_bottom_half_tx+0xb88/0xd00 kasan_report+0xb8/0xf0 ? do_bottom_half_tx+0xb88/0xd00 do_bottom_half_tx+0xb88/0xd00 ? _raw_spin_lock_irqsave+0x85/0xe0 ? __pfx__raw_spin_lock_irqsave+0x10/0x10 ? __pfx___hrtimer_run_queues+0x10/0x10 fst_process_tx_work_q+0x67/0x90 tasklet_action_common+0x1fa/0x720 ? hrtimer_interrupt+0x31f/0x780 handle_softirqs+0x176/0x530 __irq_exit_rcu+0xab/0xe0 sysvec_apic_timer_interrupt+0x70/0x80 ... Allocated by task 41 on cpu 3 at 72.330843s: kasan_save_stack+0x24/0x50 kasan_save_track+0x17/0x60 __kasan_kmalloc+0x7f/0x90 fst_add_one+0x1a5/0x1cd0 local_pci_probe+0xdd/0x190 pci_device_probe+0x341/0x480 really_probe+0x1c6/0x6a0 __driver_probe_device+0x248/0x310 driver_probe_device+0x48/0x210 __device_attach_driver+0x160/0x320 bus_for_each_drv+0x101/0x190 __device_attach+0x198/0x3a0 device_initial_probe+0x78/0xa0 pci_bus_add_device+0x81/0xc0 pci_bus_add_devices+0x7e/0x190 enable_slot+0x9b9/0x1130 acpiphp_check_bridge.part.0+0x2e1/0x460 acpiphp_hotplug_notify+0x36c/0x3c0 acpi_device_hotplug+0x203/0xb10 acpi_hotplug_wo

Affected

76 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 2f623aaf9f31de968dea6169849706a2f9be444c < 337d7b4112a47984ee319171b75b73bab47e7924337d7b4112a47984ee319171b75b73bab47e7924
linuxlinux>= 2f623aaf9f31de968dea6169849706a2f9be444c < 200bdb8d367ca9b478f9c56ebe56411604d55c81200bdb8d367ca9b478f9c56ebe56411604d55c81
linuxlinux>= 2f623aaf9f31de968dea6169849706a2f9be444c < 21d341fe514fd07e345ed264c9eee21cb2061ca221d341fe514fd07e345ed264c9eee21cb2061ca2
linuxlinux>= 2f623aaf9f31de968dea6169849706a2f9be444c < 04edfdfdfcdefc02408ab670607261b0a0a9a02e04edfdfdfcdefc02408ab670607261b0a0a9a02e
linuxlinux>= 2f623aaf9f31de968dea6169849706a2f9be444c < bae8a5d2e759da2e0cba33ab2080deee96a09373bae8a5d2e759da2e0cba33ab2080deee96a09373
linuxlinux>= 4.14.303 < 4.154.15
linuxlinux>= 4.19.270 < 4.204.20
linuxlinux>= 4.9.337 < 4.104.10
linuxlinux>= 5.10.163 < 5.10.2525.10.252
linuxlinux>= 5.15.86 < 5.15.2025.15.202
linuxlinux>= 5.4.229 < 5.55.5
linuxlinux>= 51e2d1b84acac39f79cacb60e6e154ce00a9d308 < cac048ebfbb92d91d719f74b59177cb70a7633b8cac048ebfbb92d91d719f74b59177cb70a7633b8
linuxlinux>= 6.0.16 < 6.16.1
linuxlinux>= 6.1.2 < 6.1.1656.1.165
linuxlinux>= 998b4e54f517961d3d75144c088a24423e003005 < 086131807d119238cd464e5b0845e48d938dfd79086131807d119238cd464e5b0845e48d938dfd79
linuxlinux>= bb1715a6bfb0c57a68524732a376498a2569f016 < ae894e47e1cd5a6bf8a0423d888c45df8b2b02dcae894e47e1cd5a6bf8a0423d888c45df8b2b02dc
linuxlinux_kernel
linuxlinux_kernel>= 4.14.303 < 4.154.15
linuxlinux_kernel>= 4.19.270 < 4.204.20

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.