Junglewise Threat Intelligence

CVE-2026-43180: Linux Kernel race condition in kaweth USB Ethernet driver

CVE-2026-43180 · Severity: high · CVSS 7.8 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's driver for certain USB Ethernet adapters. The issue involves improper management of data transmission queues when changing network settings, which could lead to system instability or crashes. This affects systems using specific legacy USB networking hardware, potentially allowing a local user to disrupt operations or compromise the system.

Technical details

A vulnerability exists in the kaweth driver (drivers/net/usb/kaweth.c) within the Linux kernel due to improper TX queue manipulation in the kaweth_set_rx_mode() function. The function incorrectly calls netif_stop_queue() and netif_wake_queue(), which are TX flow control functions, during RX multicast configuration. This premature waking of the TX queue allows kaweth_start_xmit() to be called while a previous USB Request Block (URB) is still in-flight, resulting in a double usb_submit_urb() call. This triggers a kernel warning ('URB submitted while active') and can lead to undefined behavior or system crashes. The fix involves removing the disruptive TX queue manipulation from the RX mode configuration path.

Affected products

  • Linux Linux Kernel 2.6.12-rc2 to 5.10.252, 5.11 to 5.15.202, 5.16 to 6.1.165, 6.2 to 6.6.128, 6.7 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6

Timeline

  • 2026-02-17: other: Patch authored
  • 2026-05-06: disclosed: CVE published

References

Related threats