CVE-2026-43015: net: macb: fix clk handling on PCI glue driver removal

Published May 1, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

net: macb: fix clk handling on PCI glue driver removal

platformdeviceunregister() may still want to use the registered clks during runtime resume callback.

Note that there is a commit d82d5303c4c5 ("net: macb: fix use after free on rmmod") that addressed the similar problem of clk vs platform device unregistration but just moved the bug to another place.

Save the pointers to clks into local variables for reuse after platform device is unregistered.

BUG: KASAN: use-after-free in clkprepare+0x5a/0x60 Read of size 8 at addr ffff888104f85e00 by task modprobe/597

CPU: 2 PID: 597 Comm: modprobe Not tainted 6.1.164+ #114 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.1-0-g3208b098f51a-prebuilt.qemu.org 04/01/2014 Call Trace: <TASK> dumpstacklvl+0x8d/0xba printreport+0x17f/0x496 kasanreport+0xd9/0x180 clkprepare+0x5a/0x60 macbruntimeresume+0x13d/0x410 [macb] pmgenericruntimeresume+0x97/0xd0 rpmcallback+0xc8/0x4d0 rpmcallback+0xf6/0x230 rpmresume+0xeeb/0x1a70 pmruntimeresume+0xb4/0x170 busremovedevice+0x2e3/0x4b0 devicedel+0x5b3/0xdc0 platformdevicedel+0x4e/0x280 platformdeviceunregister+0x11/0x50 pcideviceremove+0xae/0x210 deviceremove+0xcb/0x180 devicereleasedriverinternal+0x529/0x770 driverdetach+0xd4/0x1a0 busremovedriver+0x135/0x260 driverunregister+0x72/0xb0 pciunregisterdriver+0x26/0x220 dosysdeletemodule+0x32e/0x550 dosyscall64+0x35/0x80 entrySYSCALL64afterhwframe+0x6e/0xd8 </TASK>

Allocated by task 519: kasansavestack+0x2c/0x50 kasansettrack+0x21/0x30 kasankmalloc+0x8e/0x90 clkregister+0x458/0x2890 clkhwregister+0x1a/0x60 clkhwregisterfixedrate+0x255/0x410 clkregisterfixedrate+0x3c/0xa0 macbprobe+0x1d8/0x42e [macbpci] localpciprobe+0xd7/0x190 pcideviceprobe+0x252/0x600 reallyprobe+0x255/0x7f0 driverprobedevice+0x1ee/0x330 driverprobedevice+0x4c/0x1f0 driverattach+0x1df/0x4e0 busforeachdev+0x15d/0x1f0 busadddriver+0x486/0x5e0 driverregister+0x23a/0x3d0 dooneinitcall+0xfd/0x4d0 doinitmodule+0x18b/0x5a0 loadmodule+0x5663/0x7950 dosysfinitmodule+0x101/0x180 dosyscall64+0x35/0x80 entrySYSCALL64afterhwframe+0x6e/0xd8

Freed by task 597: kasansavestack+0x2c/0x50 kasansettrack+0x21/0x30 kasansavefreeinfo+0x2a/0x50 kasanslabfree+0x106/0x180 kmemcachefree+0xbc/0x320 clkunregister+0x6de/0x8d0 macbremove+0x73/0xc0 [macbpci] pcideviceremove+0xae/0x210 deviceremove+0xcb/0x180 devicereleasedriverinternal+0x529/0x770 driverdetach+0xd4/0x1a0 busremovedriver+0x135/0x260 driverunregister+0x72/0xb0 pciunregisterdriver+0x26/0x220 dosysdeletemodule+0x32e/0x550 dosyscall64+0x35/0x80 entrySYSCALL64afterhwframe+0x6e/0xd8

Affected Software

25 affected components
Linux Linux kernel
Linux Linux kernel>=4.14.249<4.15
Linux Linux kernel>=4.19.209<4.20
Linux Linux kernel>=5.4.150<5.5
Linux Linux kernel>=5.10.70<5.10.253
Linux Linux kernel>=5.14.9<5.15
Linux Linux kernel>=5.15.1<5.15.203
Linux Linux kernel>=5.16<6.1.168
Linux Linux kernel>=6.2<6.6.134
Linux Linux kernel>=6.7<6.12.81
Linux Linux kernel>=6.13<6.18.22
Linux Linux kernel>=6.19<6.19.12
Linux Linux kernel=5.15
Linux Linux kernel=5.15-rc2
Linux Linux kernel=5.15-rc3
Linux Linux kernel=5.15-rc4
Linux Linux kernel=5.15-rc5
Linux Linux kernel=5.15-rc6
Linux Linux kernel=5.15-rc7
Linux Linux kernel=7.0-rc1
Linux Linux kernel=7.0-rc2
Linux Linux kernel=7.0-rc3
Linux Linux kernel=7.0-rc4
Linux Linux kernel=7.0-rc5
Linux Linux kernel=7.0-rc6

Event History

May 1, 2026
CVE Published
via MITRE·02:15 PM
Data Sourced
via MITRE·02:15 PM
Description
Data Sourced
via NVD·03:16 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-43015?

CVE-2026-43015 is classified as a vulnerability affecting the Linux kernel that involves improper clk handling during PCI glue driver removal.

2

How do I fix CVE-2026-43015?

To fix CVE-2026-43015, ensure that the Linux kernel is updated to the latest patched version that addresses this vulnerability.

3

What software is affected by CVE-2026-43015?

CVE-2026-43015 affects the Linux kernel, specifically its handling of PCI glue drivers.

4

What are the potential impacts of exploiting CVE-2026-43015?

Exploiting CVE-2026-43015 could lead to system instability or unexpected behavior during the runtime resume process.

5

Is CVE-2026-43015 a remote or local vulnerability?

CVE-2026-43015 is primarily a local vulnerability, as it relates to driver behavior within the Linux kernel.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203