Use-After-Free Vulnerability in Linux Kernel Affecting iavf Component
CVE-2026-43447

7.8HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
8 May 2026

What is CVE-2026-43447?

The iavf component in the Linux kernel suffers from a use-after-free vulnerability triggered during reset operations. This issue arises when a worker designed to cache Precision Time Protocol (PTP) time continues to operate even when the adapter resources are being freed, leading to potential access of deallocated memory. Specifically, failure to properly manage the worker during a reset or disabling of the virtual function can result in race conditions that may cause system crashes. The vulnerability has been addressed by ensuring that the PTP worker is properly released before the adapter resources are torn down, safeguarding against unexpected access to freed memory and ensuring greater system reliability.

Affected Version(s)

Linux 7c01dbfc8a1c5f8b8e4a7907ab06db1449d478d0 < 1b034f2429ce6b45ce74dc266175d277acafc5c4

Linux 7c01dbfc8a1c5f8b8e4a7907ab06db1449d478d0 < 90cc8b2add29b57288025b51c70bc647e7cccb12

Linux 7c01dbfc8a1c5f8b8e4a7907ab06db1449d478d0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.