PPPoATM uses tasklet_disable() on a tasklet inside a struct and then frees the struct, leaving a pointer to the freed tasklet inside tasklet lists. This patch replaces tasklet_disable() with tasklet_kill(). This bug is present in both 2.4.18 and 2.5.15 (and the patch applies to both). --- linux-old/net/atm/pppoatm.c Wed Apr 10 14:37:34 2002 +++ linux/net/atm/pppoatm.c Fri May 10 21:56:28 2002 @@ -125,7 +125,7 @@ pvcc = atmvcc_to_pvcc(atmvcc); atmvcc->push = pvcc->old_push; atmvcc->pop = pvcc->old_pop; - tasklet_disable(&pvcc->wakeup_tasklet); + tasklet_kill(&pvcc->wakeup_tasklet); ppp_unregister_channel(&pvcc->chan); atmvcc->user_back = NULL; kfree(pvcc);