« Volver al listado

CVE-2026-80947

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop

rtl8xxxu arms rx_urb_wq from the RX completion path: rtl8xxxu_rx_complete() hands the URB to rtl8xxxu_queue_rx_urb(), which queues it on rx_urb_pending_list and, once the list grows past RTL8XXXU_RX_URB_PENDING_WATER, schedules rx_urb_wq. The worker rtl8xxxu_rx_urb_work() drains rx_urb_pending_list, recovers priv through container_of, and resubmits each URB through rtl8xxxu_submit_rx_urb(), which anchors it on rx_anchor and dereferences priv->udev.

rtl8xxxu_stop() cancels the sibling work items (c2hcmd_work, ra_watchdog, update_beacon_work) but never cancels rx_urb_wq, so a worker armed during the last burst of RX traffic can run rtl8xxxu_rx_urb_work() after rtl8xxxu_disconnect() has called ieee80211_free_hw(), which frees priv, producing a use-after-free.

Leer descripción completaMostrar menos

The window opens under active RX traffic (pending count above the watermark) followed by a disconnect.

There are two teardown races to close:

After priv->shutdown is set under rx_urb_lock, completions can no longer queue rx_urb_wq. cancel_work_sync() then drains the last queued or running worker, and the following usb_kill_anchored_urbs() kills the URBs it may have submitted.

rtl8xxxu_disconnect() is covered because ieee80211_unregister_hw() guarantees .stop() runs for a live interface before ieee80211_free_hw() frees priv. The probe error path needs no cancel: rx_urb_wq is INIT_WORK()'d there but cannot have been scheduled, since no URB is submitted before ieee80211_register_hw() succeeds.

This bug was found by static analysis.

Detalles técnicos trazas, registros y código del informe original
  * rtl8xxxu_queue_rx_urb() decided whether to enqueue under rx_urb_lock
    but called schedule_work() after dropping the lock.  A completion
    that observed shutdown == false and released the lock could then call
    schedule_work() after rtl8xxxu_stop() had set shutdown and
    cancel_work_sync() had already returned, arming the worker to run
    after the teardown.  Move schedule_work() under the same !shutdown
    branch so the arming decision is atomic with the shutdown check.

  * rtl8xxxu_rx_urb_work() anchors every URB it drained back onto
    rx_anchor through rtl8xxxu_submit_rx_urb().  A worker still running
    when usb_kill_anchored_urbs(&priv->rx_anchor) returned would submit a
    URB that escaped the kill.  In rtl8xxxu_stop(), call
    cancel_work_sync(&priv->rx_urb_wq) before the kill so the worker is
    drained first.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de use-after-free (CWE-416) en controlador WiFi de kernel Linux con acceso local (AV:L) y privilegios limitados (PR:L). Permite ejecución de código arbitrario en contexto del kernel tras escalada de privilegios.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80947",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "26f1fad29ad973b0fb26a9ca3dcb2a73dde781aa",
              "lessThan": "800d2b490a9af1e7132a3564c2ad5a81292e5b40",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "26f1fad29ad973b0fb26a9ca3dcb2a73dde781aa",
              "lessThan": "620acb1e8037b73a457dc8ef20fc23fc7adcb405",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "26f1fad29ad973b0fb26a9ca3dcb2a73dde781aa",
              "lessThan": "972ab8b9c08f3eb3fa535082de2950dd93604dfd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "26f1fad29ad973b0fb26a9ca3dcb2a73dde781aa",
              "lessThan": "6c080026ecc17eecb103f8927c64ea73a74bb818",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/wireless/realtek/rtl8xxxu/core.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.4"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.4",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.109",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.50",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/wireless/realtek/rtl8xxxu/core.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:19:00.303",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/620acb1e8037b73a457dc8ef20fc23fc7adcb405",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6c080026ecc17eecb103f8927c64ea73a74bb818",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/800d2b490a9af1e7132a3564c2ad5a81292e5b40",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/972ab8b9c08f3eb3fa535082de2950dd93604dfd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop\n\nrtl8xxxu arms rx_urb_wq from the RX completion path:\nrtl8xxxu_rx_complete() hands the URB to rtl8xxxu_queue_rx_urb(), which\nqueues it on rx_urb_pending_list and, once the list grows past\nRTL8XXXU_RX_URB_PENDING_WATER, schedules rx_urb_wq.  The worker\nrtl8xxxu_rx_urb_work() drains rx_urb_pending_list, recovers priv through\ncontainer_of, and resubmits each URB through rtl8xxxu_submit_rx_urb(),\nwhich anchors it on rx_anchor and dereferences priv->udev.\n\nrtl8xxxu_stop() cancels the sibling work items (c2hcmd_work, ra_watchdog,\nupdate_beacon_work) but never cancels rx_urb_wq, so a worker armed during\nthe last burst of RX traffic can run rtl8xxxu_rx_urb_work() after\nrtl8xxxu_disconnect() has called ieee80211_free_hw(), which frees priv,\nproducing a use-after-free.  The window opens under active RX traffic\n(pending count above the watermark) followed by a disconnect.\n\nThere are two teardown races to close:\n\n  * rtl8xxxu_queue_rx_urb() decided whether to enqueue under rx_urb_lock\n    but called schedule_work() after dropping the lock.  A completion\n    that observed shutdown == false and released the lock could then call\n    schedule_work() after rtl8xxxu_stop() had set shutdown and\n    cancel_work_sync() had already returned, arming the worker to run\n    after the teardown.  Move schedule_work() under the same !shutdown\n    branch so the arming decision is atomic with the shutdown check.\n\n  * rtl8xxxu_rx_urb_work() anchors every URB it drained back onto\n    rx_anchor through rtl8xxxu_submit_rx_urb().  A worker still running\n    when usb_kill_anchored_urbs(&priv->rx_anchor) returned would submit a\n    URB that escaped the kill.  In rtl8xxxu_stop(), call\n    cancel_work_sync(&priv->rx_urb_wq) before the kill so the worker is\n    drained first.\n\nAfter priv->shutdown is set under rx_urb_lock, completions can no longer\nqueue rx_urb_wq. cancel_work_sync() then drains the last queued or running\nworker, and the following usb_kill_anchored_urbs() kills the URBs it may\nhave submitted.\n\nrtl8xxxu_disconnect() is covered because ieee80211_unregister_hw()\nguarantees .stop() runs for a live interface before ieee80211_free_hw()\nfrees priv.  The probe error path needs no cancel: rx_urb_wq is\nINIT_WORK()'d there but cannot have been scheduled, since no URB is\nsubmitted before ieee80211_register_hw() succeeds.\n\nThis bug was found by static analysis."
    }
  ],
  "lastModified": "2026-09-13T07:17:01.960",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}