Executive brief
A race condition exists in the Linux kernel's mptlan network device driver during device removal. When the driver is unloaded, freed memory can be accessed by a background work task, potentially causing a kernel crash or memory corruption that could compromise system stability or be exploited for privilege escalation.
Technical details
This is a use-after-free vulnerability (CWE-416) in the mptlan SCSI message driver. The mptlan_remove() function frees the network device structure via free_netdev() without first stopping the &priv->post_buckets_task delayed workqueue, which may still be executing. A concurrent work function (mpt_lan_post_receive_buckets_work()) on another CPU can then access freed memory (dev->mtu) after free_netdev() deallocates the device. The vulnerability requires the driver to be actively unloading while the work queue is scheduled. The fix, committed in upstream Linux kernel, adds a cancel_delayed_work_sync() call before cleanup to ensure the work completes or is cancelled before the device is freed.
Affected products
- Linux Linux kernel All versions with mptlan driver (mptlan.c in drivers/message/fusion/)
Timeline
- 2023-03-18: disclosed: Patch authored by Zheng Wang
- 2023-05-24: patched: Patch merged into stable tree (commit f486893288f3e9b171b836f43853a6426515d800)
- 2025-12-30: advisory: CVE-2023-54310 published