CVE-2026-43203 Details
Description
In the Linux kernel, the following vulnerability has been resolved: atm: fore200e: fix use-after-free in tasklets during device removal When the PCA-200E or SBA-200E adapter is being detached, the fore200e is deallocated. However, the tx_tasklet or rx_tasklet may still be running or pending, leading to use-after-free bug when the already freed fore200e is accessed again in fore200e_tx_tasklet() or fore200e_rx_tasklet(). One of the race conditions can occur as follows: CPU 0 (cleanup) | CPU 1 (tasklet) fore200e_pca_remove_one() | fore200e_interrupt() fore200e_shutdown() | tasklet_schedule() kfree(fore200e) | fore200e_tx_tasklet() | fore200e-> // UAF Fix this by ensuring tx_tasklet or rx_tasklet is properly canceled before the fore200e is released. Add tasklet_kill() in fore200e_shutdown() to synchronize with any pending or running tasklets. Moreover, since fore200e_reset() could prevent further interrupts or data transfers, the tasklet_kill() should be placed after fore200e_reset() to prevent the tasklet from being rescheduled in fore200e_interrupt(). Finally, it only needs to do tasklet_kill() when the fore200e state is greater than or equal to FORE200E_STATE_IRQ, since tasklets are uninitialized in earlier states. In a word, the tasklet_kill() should be placed in the FORE200E_STATE_IRQ branch within the switch...case structure. This bug was identified through static analysis.
A use-after-free vulnerability has been identified in the Linux kernel's ATM fore200e driver, specifically related to the PCA-200E and SBA-200E adapters. When these adapters are detached, the associated fore200e structure is deallocated. However, the transmission and reception tasklets may still be active or pending. This can lead to a race condition where the freed fore200e structure is accessed again by the tasklets, causing a use-after-free bug. The vulnerability arises because the tasklets are not properly synchronized with the device removal process, allowing them to operate on deallocated memory.
The vulnerability has been fixed by ensuring that the transmission and reception tasklets are properly canceled before the fore200e structure is released. This is done by adding the 'tasklet_kill()' function in the 'fore200e_shutdown()' function, which is responsible for cleaning up the device before it is deallocated. The 'tasklet_kill()' function should only be called when the fore200e state is ready for tasklets to be safely terminated.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/5189368f10903956be05062d160b2804bf5e5016 | kernel.org | Patch |
| https://git.kernel.org/stable/c/73fbc5d1a9ccb626937500bbd67136f077d8237b | kernel.org | Patch |
| https://git.kernel.org/stable/c/8930878101cd40063888a68af73b1b0f8b6c79bc | kernel.org | Patch |
| https://git.kernel.org/stable/c/91f25749aaf57c47ae1e12478144e6ea8c8562f2 | kernel.org | Patch |
| https://git.kernel.org/stable/c/97900f512252a59f23d6ce4ab215cc88fed66e68 | kernel.org | Patch |
| https://git.kernel.org/stable/c/aba0b4bc09376dfc3d53c826514fe38fc8337f52 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e075ec9b08f862dade8011481058f7eb5f716c57 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e4ff4e3ffcf9d5aad380cdd1d8cdc008bb34f97d | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.12.1, < 5.10.252 >= 5.11, < 5.15.202 >= 5.16, < 6.1.165 >= 6.2, < 6.6.128 >= 6.7, < 6.12.75 >= 6.13, < 6.18.16 >= 6.19, < 6.19.6 2.6.12 - 2.6.12 rc2 2.6.12 rc3 2.6.12 rc4 2.6.12 rc5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 11, 2026 | Initial Analysis | [email protected] |
| May 8, 2026 | CVE Modified | kernel.org |
| May 6, 2026 | New CVE Received | kernel.org |