CVE-2026-43293

MEDIUM EPSS 2.3%
Published May 8, 20261mo ago · Modified Jun 17, 20262w ago
5.5 CVSS 3.1
Medium
Find Similar
Published May 8, 2026 1mo ago
Last Modified Jun 17, 2026 2w ago

Description

In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Fix kthread worker destruction in polling mode Fix the cleanup order in polling mode (irq < 0) to prevent kernel warnings during module removal. Cancel the hrtimer before destroying the kthread worker to ensure work queues are empty. In polling mode, the driver uses hrtimer to periodically trigger wave5_vpu_timer_callback() which queues work via kthread_queue_work(). The kthread_destroy_worker() function validates that both work queues are empty with WARN_ON(!list_empty(&worker->work_list)) and WARN_ON(!list_empty(&worker->delayed_work_list)). The original code called kthread_destroy_worker() before hrtimer_cancel(), creating a race condition where the timer could fire during worker destruction and queue new work, triggering the WARN_ON. This causes the following warning on every module unload in polling mode: ------------[ cut here ]------------ WARNING: CPU: 2 PID: 1034 at kernel/kthread.c:1430 kthread_destroy_worker+0x84/0x98 Modules linked in: wave5(-) rpmsg_ctrl rpmsg_char ... Call trace: kthread_destroy_worker+0x84/0x98 wave5_vpu_remove+0xc8/0xe0 [wave5] platform_remove+0x30/0x58 ... ---[ end trace 0000000000000000 ]---

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
2.3% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Affected Products 3

VendorProductVersionRange
linuxlinux_kernel*≥6.10  –  <6.12.75
linuxlinux_kernel*≥6.13  –  <6.18.16
linuxlinux_kernel*≥6.19  –  <6.19.6

References 4

  • git.kernel.org https://git.kernel.org/stable/c/0c2e752688a0ee3b89993e6de6c496d863870c93
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/156020e889edf4593870d926d3c4a6d06baac44a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/5a0c122e834b2f7f029526422c71be922960bf03
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/cc8071b1bac6568ea09d54be2d4f74dba80e17f8
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/0c2e752688a0ee3b89993e6de6c496d863870c93
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/156020e889edf4593870d926d3c4a6d06baac44a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/5a0c122e834b2f7f029526422c71be922960bf03
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/cc8071b1bac6568ea09d54be2d4f74dba80e17f8
    Patch