From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DA2F42C11E4; Wed, 23 Sep 2026 14:32:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790173927; cv=none; b=GMd4ue8EKvg4YRm3JweHEIV0LH3Cd1vUbiAyvVCPOlrR1PCue+ZWOJknpg6koPHg40Den2esrjhNQGQ7dUP0fIlKA5Ep/XQmXzvqS8iXXBVhdMqGPNpWTvHgEIzT3QfOphkwbDkV2csuGr/jd7JzktN2qv8mnZ3HTU9LPxznHVk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790173927; c=relaxed/simple; bh=gE7clvhbZP3OCzFJPELwDWVEk8/mr41wMpS8+XbB8Rg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=pzl4ZURRK3Dz7lhRMRAvixDulk7v+BUoShBlZrpHPq9xLcMjRWdqSeLfM8ICWAZNMoX+LW+WS3+ByOXDSeYxxm7O+Ms+J4lZCcwF1UCvh4CWjoE402pVThSgIsfOp7/BDSBengRFyB5cpiSePuiZLCXRu2XbLs6Uqu660L05e4A= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=WWSSaR/L; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="WWSSaR/L" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 2F7C01F00898; Wed, 23 Sep 2026 14:32:05 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790173925; bh=Y+JY0ZOjnHertGHSVNr8YUOCEgeHrFNvzMFMcRr5wIY=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=WWSSaR/LPoe0BJ8ESduLCHR5vQj3FHu6oQNirig1+Xx8CA+UjGupOSKFvYYR+znKi pItEJcJw12fW4EGlDe8KcelPodfxWn5Q+O/apPuH+wGVX5HX589HgPjuOmhtSof1j+ q45uMd/EU8zwTY07BAXqC3GCcPHGLi9ySlp1YiFo= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Song Li , Fan Wu , Loic Poulain , Jeff Johnson Subject: [PATCH 7.2 387/438] wifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown Date: Wed, 23 Sep 2026 16:06:48 +0200 Message-ID: <20260923140654.908312277@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260923140644.756254324@linuxfoundation.org> References: <20260923140644.756254324@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 7.2-stable review patch. If anyone has any objections, please let me know. ------------------ From: Fan Wu commit d9be5e75530772fc31637070d51e5717d6aeaa2a upstream. wcn36xx_dxe_deinit() tears down the TX ack timer with timer_delete(), which only dequeues the timer and does not wait for a callback that is already executing; the preceding free_irq() calls synchronize the interrupt handlers only. The callback, wcn36xx_dxe_tx_timer(), can therefore be running past the teardown and use the wcn freed along with the ieee80211_hw in wcn36xx_remove(): it takes wcn->dxe_lock, reads wcn->tx_ack_skb and passes wcn->hw to ieee80211_tx_status_irqsafe(). Fix this by using timer_shutdown_sync(), which waits for a running callback and also prevents the timer from being rearmed again. The timer is set up again by wcn36xx_dxe_init() on the next start, so the start/stop cycle is unaffected. This issue was found by an in-house static analysis tool. Fixes: fdf21cc37149 ("wcn36xx: Add TX ack support") Cc: stable@vger.kernel.org Assisted-by: LLM Co-developed-by: Song Li Signed-off-by: Song Li Signed-off-by: Fan Wu Reviewed-by: Loic Poulain Link: https://patch.msgid.link/20260910020907.3353-1-fanwu01@zju.edu.cn Signed-off-by: Jeff Johnson Signed-off-by: Greg Kroah-Hartman --- drivers/net/wireless/ath/wcn36xx/dxe.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) --- a/drivers/net/wireless/ath/wcn36xx/dxe.c +++ b/drivers/net/wireless/ath/wcn36xx/dxe.c @@ -1055,7 +1055,7 @@ void wcn36xx_dxe_deinit(struct wcn36xx * free_irq(wcn->tx_irq, wcn); free_irq(wcn->rx_irq, wcn); - timer_delete(&wcn->tx_ack_timer); + timer_shutdown_sync(&wcn->tx_ack_timer); if (wcn->tx_ack_skb) { ieee80211_tx_status_irqsafe(wcn->hw, wcn->tx_ack_skb);