Junglewise Threat Intelligence

CVE-2026-43479: Linux kernel lan78xx redundant NAPI deletion on disconnect

CVE-2026-43479 · Severity: info · Published 2026-05-13

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A technical issue was identified in the Linux kernel's driver for Microchip LAN78xx USB Ethernet adapters. When a user disconnects the USB device, the system may trigger an internal warning or error because the driver attempts to shut down network processing twice. While primarily a stability concern, it could lead to unexpected system behavior or crashes during device removal.

Technical details

A vulnerability in the lan78xx USB Ethernet driver (drivers/net/usb/lan78xx.c) causes a kernel WARNING in __netif_napi_del_locked() during device disconnection. The root cause is a redundant call to netif_napi_del() in the lan78xx_disconnect() path while NAPI is still enabled. Since unregister_netdev() already handles NAPI teardown safely, this explicit call is unnecessary and violates kernel state expectations. An attacker with physical access could potentially exploit this state inconsistency by repeatedly connecting/disconnecting devices to trigger kernel instability, though it is currently rated as 'info' severity. The fix involves removing the redundant netif_napi_del() call.

Affected products

  • Linux Linux kernel 6.16.0-rc2-00624-ge926949dab03

Timeline

  • 2026-03-05: other: Patch authored
  • 2026-03-19: patched: Patch committed to stable tree
  • 2026-05-13: disclosed: CVE published

References

Related threats