CVE-2026-43293 Details
Description
In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Fix kthread worker destruction in polling mode Fix the cleanup order in polling mode (irq < 0) to prevent kernel warnings during module removal. Cancel the hrtimer before destroying the kthread worker to ensure work queues are empty. In polling mode, the driver uses hrtimer to periodically trigger wave5_vpu_timer_callback() which queues work via kthread_queue_work(). The kthread_destroy_worker() function validates that both work queues are empty with WARN_ON(!list_empty(&worker->work_list)) and WARN_ON(!list_empty(&worker->delayed_work_list)). The original code called kthread_destroy_worker() before hrtimer_cancel(), creating a race condition where the timer could fire during worker destruction and queue new work, triggering the WARN_ON. This causes the following warning on every module unload in polling mode: ------------[ cut here ]------------ WARNING: CPU: 2 PID: 1034 at kernel/kthread.c:1430 kthread_destroy_worker+0x84/0x98 Modules linked in: wave5(-) rpmsg_ctrl rpmsg_char ... Call trace: kthread_destroy_worker+0x84/0x98 wave5_vpu_remove+0xc8/0xe0 [wave5] platform_remove+0x30/0x58 ... ---[ end trace 0000000000000000 ]---
A race condition vulnerability has been identified in the Linux kernel's chips-media wave5 driver, specifically in the handling of kthread workers during module removal. This issue arises in polling mode when the interrupt request (irq) is less than zero. The driver utilizes a high-resolution timer (hrtimer) to periodically trigger a callback that queues work for processing. However, the original cleanup sequence canceled the timer after initiating the destruction of the kthread worker. This flaw allowed the timer to potentially fire during the worker's removal, leading to new work being queued and causing kernel warnings. The vulnerability has been addressed by adjusting the cleanup order to ensure that work queues are empty before the kthread worker is destroyed.
The vulnerability has been fixed in the Linux kernel. Users should upgrade to the latest version where this issue has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0c2e752688a0ee3b89993e6de6c496d863870c93 | kernel.org | Patch |
| https://git.kernel.org/stable/c/156020e889edf4593870d926d3c4a6d06baac44a | kernel.org | Patch |
| https://git.kernel.org/stable/c/5a0c122e834b2f7f029526422c71be922960bf03 | kernel.org | Patch |
| https://git.kernel.org/stable/c/cc8071b1bac6568ea09d54be2d4f74dba80e17f8 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.10, < 6.12.75 >= 6.13, < 6.18.16 >= 6.19, < 6.19.6 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 14, 2026 | Initial Analysis | [email protected] |
| May 8, 2026 | New CVE Received | kernel.org |