Executive brief
A vulnerability exists in the Linux kernel driver for FarSync T-series WAN cards. When the hardware card is removed or the driver is detached, the system may attempt to access memory that has already been deleted. This can lead to system instability, crashes, or potential unauthorized access to sensitive data.
Technical details
A use-after-free (UAF) vulnerability exists in drivers/net/wan/farsync.c within the Linux kernel. The root cause is a race condition where fst_remove_one() deallocates the fst_card_info structure while fst_tx_task or fst_int_task tasklets are still pending or executing. When these tasklets eventually run, they attempt to access the already freed fst_card_info memory. An attacker could potentially exploit this via network-triggered events that schedule these tasklets during a device detach event. The fix involves calling tasklet_kill() for both the transmit and interrupt tasklets before memory deallocation to ensure synchronization.
Affected products
- Linux Linux Kernel 4.9.337 to 4.10, 4.14.303 to 4.15, 4.19.270 to 4.20, 5.4.229 to 5.5, 6.0.16 to 6.1, 6.2 to 6.6.128, 6.7 to 6.12.75, 6.13 to 6.18.16
Timeline
- 2026-02-19: patched: Initial patch submitted by Duoming Zhou
- 2026-05-06: advisory: CVE-2026-43232 published
References
- https://git.kernel.org/stable/c/04edfdfdfcdefc02408ab670607261b0a0a9a02e
- https://git.kernel.org/stable/c/086131807d119238cd464e5b0845e48d938dfd79
- https://git.kernel.org/stable/c/200bdb8d367ca9b478f9c56ebe56411604d55c81
- https://git.kernel.org/stable/c/21d341fe514fd07e345ed264c9eee21cb2061ca2
- https://git.kernel.org/stable/c/337d7b4112a47984ee319171b75b73bab47e7924
- https://git.kernel.org/stable/c/ae894e47e1cd5a6bf8a0423d888c45df8b2b02dc
- https://git.kernel.org/stable/c/bae8a5d2e759da2e0cba33ab2080deee96a09373