From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 72545332EC5; Wed, 23 Sep 2026 14:51:58 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790175120; cv=none; b=aeDtkah0PRF4YF3ytueq0B7mIKAhVQz1l9VOg4bjxT1PD2rczSKp2qMrvLfljTxmb1ankNgURvgJCWkAYQYgXGIIU8JCWCMruE2WJga5zKfApwuEJyLXDUgu6V4c7R5Kg024ABqXytvcBTHSeJJW7w/QgoIZBgtCc0JYaaoGWCk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790175120; c=relaxed/simple; bh=DTCPX/UXlCAAlpUbko/DKDo3pL2emwGpl9RC0/KkkFM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=rTyF4c5dgxxpSZhbxKjMO5eP0sPIoTES0V1iWxhu1f5XuWiQlAvusmTXgrCudda4NotjPP9mJV9hFJ5sdpQK9nrx/vKBSeYhjttvWxALBTRcJqKiK3tOrL+juJjZbSQDpGzAx+S3q+MjUdAEyxOd6FO6ZT4yBElHfuFd/G5NgpA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=r2im2wy1; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="r2im2wy1" Received: by smtp.kernel.org (Postfix) with ESMTPSA id CC2311F00893; Wed, 23 Sep 2026 14:51:57 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790175118; bh=SWsd11b+o88AS9eAPg9xoX5ccvOhfTa6hd2mua5dNY8=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=r2im2wy1D/e/f2SWGrjZFr/LhAQkO2jhVVN3012S+Cae9Snqm4Aks2k3aCK0/eVYN /pBBBlOpcHsV0DOK7MM72Y2nP80Z8OPcRfup11Ip4wheTEQzgTrzbg+S1Ek2QzHacK i+ArbmmnBltKtSUgtPmMnc4Tv+BqejrljHluzRvM= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Song Li , Fan Wu , Loic Poulain , Jeff Johnson Subject: [PATCH 6.18 327/398] wifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown Date: Wed, 23 Sep 2026 16:06:41 +0200 Message-ID: <20260923140651.898030798@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260923140643.441954610@linuxfoundation.org> References: <20260923140643.441954610@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.18-stable review patch. If anyone has any objections, please let me know. ------------------ From: Fan Wu commit d9be5e75530772fc31637070d51e5717d6aeaa2a upstream. wcn36xx_dxe_deinit() tears down the TX ack timer with timer_delete(), which only dequeues the timer and does not wait for a callback that is already executing; the preceding free_irq() calls synchronize the interrupt handlers only. The callback, wcn36xx_dxe_tx_timer(), can therefore be running past the teardown and use the wcn freed along with the ieee80211_hw in wcn36xx_remove(): it takes wcn->dxe_lock, reads wcn->tx_ack_skb and passes wcn->hw to ieee80211_tx_status_irqsafe(). Fix this by using timer_shutdown_sync(), which waits for a running callback and also prevents the timer from being rearmed again. The timer is set up again by wcn36xx_dxe_init() on the next start, so the start/stop cycle is unaffected. This issue was found by an in-house static analysis tool. Fixes: fdf21cc37149 ("wcn36xx: Add TX ack support") Cc: stable@vger.kernel.org Assisted-by: LLM Co-developed-by: Song Li Signed-off-by: Song Li Signed-off-by: Fan Wu Reviewed-by: Loic Poulain Link: https://patch.msgid.link/20260910020907.3353-1-fanwu01@zju.edu.cn Signed-off-by: Jeff Johnson Signed-off-by: Greg Kroah-Hartman --- drivers/net/wireless/ath/wcn36xx/dxe.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) --- a/drivers/net/wireless/ath/wcn36xx/dxe.c +++ b/drivers/net/wireless/ath/wcn36xx/dxe.c @@ -1055,7 +1055,7 @@ void wcn36xx_dxe_deinit(struct wcn36xx * free_irq(wcn->tx_irq, wcn); free_irq(wcn->rx_irq, wcn); - timer_delete(&wcn->tx_ack_timer); + timer_shutdown_sync(&wcn->tx_ack_timer); if (wcn->tx_ack_skb) { ieee80211_tx_status_irqsafe(wcn->hw, wcn->tx_ack_skb);