* CVE-2026-68363: wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request
@ 2026-08-10 12:01 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-08-10 12:01 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request
ath9k_hif_request_firmware() re-arms an asynchronous firmware load via
request_firmware_nowait(), passing hif_dev as the completion context, and
then still dereferences hif_dev:
dev_info(&hif_dev->udev->dev, "ath9k_htc: Firmware %s requested\n",
hif_dev->fw_name);
The re-armed callback ath9k_hif_usb_firmware_cb() runs on the "events"
workqueue and, when the firmware is missing, walks the retry chain into
ath9k_hif_usb_firmware_fail() -> complete_all(&hif_dev->fw_done). That
releases the wait_for_completion(&hif_dev->fw_done) in a concurrent
ath9k_hif_usb_disconnect(), which then kfree()s hif_dev. The trailing
dev_info() in the frame that re-armed the request can therefore read freed
memory (hif_dev->udev, the first field of struct hif_device_usb):
BUG: KASAN: slab-use-after-free in ath9k_hif_request_firmware
Read of size 8 ... by task kworker/...
ath9k_hif_request_firmware
ath9k_hif_usb_firmware_cb drivers/net/wireless/ath/ath9k/hif_usb.c:1247
request_firmware_work_func
Allocated by ...:
ath9k_hif_usb_probe drivers/net/wireless/ath/ath9k/hif_usb.c
Freed by ...:
ath9k_hif_usb_disconnect -> kfree drivers/net/wireless/ath/ath9k/hif_usb.c
The fw_done barrier only makes disconnect wait for the firmware chain to
*terminate*; it does not protect the outer ath9k_hif_request_firmware()
frame that re-armed the request and keeps touching hif_dev afterwards.
Drop the post-request dev_info(): it is the only use of hif_dev after the
async request is armed, and it is purely informational (the dev_err() on the
failure path runs only when request_firmware_nowait() did not arm a callback,
so hif_dev is still alive there).
This was first reported by syzbot as a single, non-reproduced crash that was
later auto-obsoleted, and was independently rediscovered by the reFuzz fuzzer,
which produced a C reproducer (USB-gadget connect/disconnect of an ath9k_htc
device whose firmware download fails). The vulnerable code is unchanged and
still present in v7.1-rc6, where the slab-use-after-free reproduces under KASAN
once the (sub-microsecond) race window is widened.
The Linux kernel CVE team has assigned CVE-2026-68363 to this issue.
Affected and fixed versions
===========================
Issue introduced in 4.4 with commit e904cf6fe23022cde4e0ea9d41601411a315a3dc and fixed in 6.6.148 with commit 7f184ca38a90889f3f6665ff96748b95da39dbee
Issue introduced in 4.4 with commit e904cf6fe23022cde4e0ea9d41601411a315a3dc and fixed in 6.12.101 with commit 10b0ce629123a3737b4eda50188f73bb7be7b68b
Issue introduced in 4.4 with commit e904cf6fe23022cde4e0ea9d41601411a315a3dc and fixed in 6.18.42 with commit 48a69cedde7388294e4ea6fd804156cd62bc04fc
Issue introduced in 4.4 with commit e904cf6fe23022cde4e0ea9d41601411a315a3dc and fixed in 7.1.6 with commit 7c9046d92c4b9789c9d9d775e4fd5f34be64cb0a
Issue introduced in 4.4 with commit e904cf6fe23022cde4e0ea9d41601411a315a3dc and fixed in 7.2-rc5 with commit dad9f96945d77ecd4708f730c06ef54dcd8cc057
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-68363
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
drivers/net/wireless/ath/ath9k/hif_usb.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/7f184ca38a90889f3f6665ff96748b95da39dbee
https://git.kernel.org/stable/c/10b0ce629123a3737b4eda50188f73bb7be7b68b
https://git.kernel.org/stable/c/48a69cedde7388294e4ea6fd804156cd62bc04fc
https://git.kernel.org/stable/c/7c9046d92c4b9789c9d9d775e4fd5f34be64cb0a
https://git.kernel.org/stable/c/dad9f96945d77ecd4708f730c06ef54dcd8cc057
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-08-10 12:13 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-10 12:01 CVE-2026-68363: wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.