LiveActive security incident?Get immediate response
CVE Record

CVE-2026-43232: net: wan: farsync: Fix use-after-free bugs caused by unfinished tasklets

In the Linux kernel, the following vulnerability has been resolved: net: wan: farsync: Fix use-after-free bugs caused by unfinished tasklets When the FarSync T-series card is being detached, the fst_card_info is deallocated in fst_remove_one(). However, the fst_tx_task or fst_int_task may still be running or pending, leading to use-after-free bugs when the already freed fst_card_info is accessed in fst_process_tx_work_q() or fst_process_int_work_q(). A typical race condition is depicted below: CPU 0 (cleanup) | CPU 1 (tasklet) | fst_start_xmit() fst_remove_one() | tasklet_schedule() unregister_hdlc_device()| | fst_process_tx_work_q() //handler kfree(card) //free | do_bottom_half_tx() | card-> //use The following KASAN trace was captured: ================================================================== BUG: KASAN: slab-use-after-free in do_bottom_half_tx+0xb88/0xd00 Read of size 4 at addr ffff88800aad101c by task ksoftirqd/3/32 ... Call Trace: <IRQ> dump_stack_lvl+0x55/0x70 print_report+0xcb/0x5d0 ? do_bottom_half_tx+0xb88/0xd00 kasan_report+0xb8/0xf0 ? do_bottom_half_tx+0xb88/0xd00 do_bottom_half_tx+0xb88/0xd00 ? _raw_spin_lock_irqsave+0x85/0xe0 ? __pfx__raw_spin_lock_irqsave+0x10/0x10 ? __pfx___hrtimer_run_queues+0x10/0x10 fst_process_tx_work_q+0x67/0x90 tasklet_action_common+0x1fa/0x720 ? hrtimer_interrupt+0x31f/0x780 handle_softirqs+0x176/0x530 __irq_exit_rcu+0xab/0xe0 sysvec_apic_timer_interrupt+0x70/0x80 ... Allocated by task 41 on cpu 3 at 72.330843s: kasan_save_stack+0x24/0x50 kasan_save_track+0x17/0x60 __kasan_kmalloc+0x7f/0x90 fst_add_one+0x1a5/0x1cd0 local_pci_probe+0xdd/0x190 pci_device_probe+0x341/0x480 really_probe+0x1c6/0x6a0 __driver_probe_device+0x248/0x310 driver_probe_device+0x48/0x210 __device_attach_driver+0x160/0x320 bus_for_each_drv+0x101/0x190 __device_attach+0x198/0x3a0 device_initial_probe+0x78/0xa0 pci_bus_add_device+0x81/0xc0 pci_bus_add_devices+0x7e/0x190 enable_slot+0x9b9/0x1130 acpiphp_check_bridge.part.0+0x2e1/0x460 acpiphp_hotplug_notify+0x36c/0x3c0 acpi_device_hotplug+0x203/0xb10 acpi_hotplug_work_fn+0x59/0x80 ... Freed by task 41 on cpu 1 at 75.138639s: kasan_save_stack+0x24/0x50 kasan_save_track+0x17/0x60 kasan_save_free_info+0x3b/0x60 __kasan_slab_free+0x43/0x70 kfree+0x135/0x410 fst_remove_one+0x2ca/0x540 pci_device_remove+0xa6/0x1d0 device_release_driver_internal+0x364/0x530 pci_stop_bus_device+0x105/0x150 pci_stop_and_remove_bus_device+0xd/0x20 disable_slot+0x116/0x260 acpiphp_disable_and_eject_slot+0x4b/0x190 acpiphp_hotplug_notify+0x230/0x3c0 acpi_device_hotplug+0x203/0xb10 acpi_hotplug_work_fn+0x59/0x80 ... The buggy address belongs to the object at ffff88800aad1000 which belongs to the cache kmalloc-1k of size 1024 The buggy address is located 28 bytes inside of freed 1024-byte region The buggy address belongs to the physical page: page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0xaad0 head: order:3 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 flags: 0x100000000000040(head|node=0|zone=1) page_type: f5(slab) raw: 0100000000000040 ffff888007042dc0 dead000000000122 0000000000000000 raw: 0000000000000000 0000000080100010 00000000f5000000 0000000000000000 head: 0100000000000040 ffff888007042dc0 dead000000000122 0000000000000000 head: 0000000000000000 0000000080100010 00000000f5000000 0000000000000000 head: 0100000000000003 ffffea00002ab401 00000000ffffffff 00000000ffffffff head: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000 page dumped because: kasan: bad access detected Memory state around the buggy address: ffff88800aad0f00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc ffff88800aad0f80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc >ffff88800aad1000: fa fb ---truncated---

HighCVSS 8.8Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

A cleanup race in Linux’s FarSync WAN-card driver can leave background tasks using card data after it is freed. This unsafe memory access can destabilize the kernel. Exposure appears concentrated in systems using FarSync T-series hardware, particularly during device detach or hot-removal; the sources do not establish widespread remote exploitability.

Executive priority

Prioritize prompt remediation on systems using FarSync T-series cards, especially where PCI hot-removal occurs. First confirm hardware and driver presence; broad emergency action across all Linux systems is unsupported by the supplied evidence.

Technical view

fst_remove_one() frees fst_card_info while fst_tx_task or fst_int_task can remain scheduled or running. Their handlers subsequently access the freed object in fst_process_tx_work_q() or fst_process_int_work_q(). KASAN captured a slab use-after-free read in do_bottom_half_tx() during PCI/ACPI removal. Referenced stable-kernel commits resolve the race; branch applicability requires verification.

Likely exposure

Likely limited to Linux hosts with affected kernels and FarSync T-series cards using the FarSync driver. The demonstrated trigger occurs while the card is detached, including PCI/ACPI hot-removal. Systems without this hardware or driver path are unlikely to be exposed. The supplied affected-version data is ambiguous, so verify exact distribution builds against vendor guidance and referenced fixes.

Exploitation context

The bundle marks KEV false and cites no exploitation in the wild or public exploit. It documents a KASAN-detected race during card removal. The supplied CVSS indicates network reachability and required user interaction, but the technical description does not establish how a remote attacker could reliably trigger the detach race.

Researcher notes

The evidence demonstrates a temporal memory-safety failure, not attacker control: cleanup on one CPU races scheduled tasklets on another. KASAN confirms a four-byte read 28 bytes into a freed 1 KiB allocation. No CWE, exploit chain, or demonstrated confidentiality or integrity impact is supplied. The CVSS vector’s AV:N/UI:R characteristics are not explained by the technical narrative.

Mitigation direction

  • Apply a distribution or vendor kernel update containing the applicable referenced Linux stable fix.
  • Until updated, avoid FarSync T-series detach or hot-removal operations where operationally safe.
  • Follow Linux and distribution guidance to identify the correct fixed build for each kernel branch.

Validation and detection

  • Inventory Linux systems with FarSync T-series cards and determine whether the FarSync driver is present and active.
  • Compare each running kernel package and source revision with distribution guidance and the applicable referenced stable commit.
  • Inspect kernel logs and crash reports for KASAN, do_bottom_half_tx, fst_process_tx_work_q, or fst_process_int_work_q indicators.
  • Confirm updated kernels include the branch-specific fix before returning normal detach or hot-removal procedures.
Prepared
Confidence
medium
Sources
10

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2026-43232 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
8.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
0ADP providers
9Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
8.8CVSS 3.1HighCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H2.85.9Linux

Vulnerability scoring details

Base CVSS 3.1 score

8.8High
CVSS 3.1 vector shape for CVE-2026-43232Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux51e2d1b84acac39f79cacb60e6e154ce00a9d308, 998b4e54f517961d3d75144c088a24423e003005, bb1715a6bfb0c57a68524732a376498a2569f016, 2f623aaf9f31de968dea6169849706a2f9be444c, 2f623aaf9f31de968dea6169849706a2f9be444c, 2f623aaf9f31de968dea6169849706a2f9be444c, 2f623aaf9f31de968dea6169849706a2f9be444c, 2f623aaf9f31de968dea6169849706a2f9be444c, 41798a063fd4721b609e11ad839b6820f5070ca7, b1fe377b43c405b169cffd1b3aa39c1dde16f3ed, ce9dc768767bbe73d2dd330a9075e849cb8a84d4, 0c5f2c7700cb18aeab1574588d3bb9c0454bf228, 024d2a7c8ee5bfe14357f20cf1bbbbcc5d228cc9, 5.10.163, 5.15.86, 6.1.2, 4.9.337, 4.14.303, 4.19.270, 5.4.229, 6.0.16unaffected
LinuxLinux6.2, 0, 5.10.252, 5.15.202, 6.1.165, 6.6.128, 6.12.75, 6.18.16, 6.19.6, 7.0affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.