CVE-2026-68363
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request
ath9k_hif_request_firmware() re-arms an asynchronous firmware load via request_firmware_nowait(), passing hif_dev as the completion context, and then still dereferences hif_dev:
The re-armed callback ath9k_hif_usb_firmware_cb() runs on the "events" workqueue and, when the firmware is missing, walks the retry chain into ath9k_hif_usb_firmware_fail() -> complete_all(&hif_dev->fw_done).
Leer descripción completaMostrar menos
That releases the wait_for_completion(&hif_dev->fw_done) in a concurrent ath9k_hif_usb_disconnect(), which then kfree()s hif_dev. The trailing dev_info() in the frame that re-armed the request can therefore read freed memory (hif_dev->udev, the first field of struct hif_device_usb):
The fw_done barrier only makes disconnect wait for the firmware chain to *terminate*; it does not protect the outer ath9k_hif_request_firmware() frame that re-armed the request and keeps touching hif_dev afterwards.
Drop the post-request dev_info(): it is the only use of hif_dev after the async request is armed, and it is purely informational (the dev_err() on the failure path runs only when request_firmware_nowait() did not arm a callback, so hif_dev is still alive there).
This was first reported by syzbot as a single, non-reproduced crash that was later auto-obsoleted, and was independently rediscovered by the reFuzz fuzzer, which produced a C reproducer (USB-gadget connect/disconnect of an ath9k_htc device whose firmware download fails). The vulnerable code is unchanged and still present in v7.1-rc6, where the slab-use-after-free reproduces under KASAN once the (sub-microsecond) race window is widened.
Detalles técnicos trazas, registros y código del informe original
dev_info(&hif_dev->udev->dev, "ath9k_htc: Firmware %s requested\n", hif_dev->fw_name); BUG: KASAN: slab-use-after-free in ath9k_hif_request_firmware Read of size 8 ... by task kworker/... ath9k_hif_request_firmware ath9k_hif_usb_firmware_cb drivers/net/wireless/ath/ath9k/hif_usb.c:1247 request_firmware_work_func Allocated by ...: ath9k_hif_usb_probe drivers/net/wireless/ath/ath9k/hif_usb.c Freed by ...: ath9k_hif_usb_disconnect -> kfree drivers/net/wireless/ath/ath9k/hif_usb.c
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 7
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/063497cc9f320ab71a7a937c3bc0a23e630aefe2
- https://git.kernel.org/stable/c/10b0ce629123a3737b4eda50188f73bb7be7b68b
- https://git.kernel.org/stable/c/47ed81aaa7f94d9808f4719e78a760c2ec1e6c86
- https://git.kernel.org/stable/c/48a69cedde7388294e4ea6fd804156cd62bc04fc
- https://git.kernel.org/stable/c/48de0c6952192b0771fca468df4364d11ec74ad9
- https://git.kernel.org/stable/c/7c9046d92c4b9789c9d9d775e4fd5f34be64cb0a
- https://git.kernel.org/stable/c/7f184ca38a90889f3f6665ff96748b95da39dbee
- https://git.kernel.org/stable/c/dad9f96945d77ecd4708f730c06ef54dcd8cc057
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-68363",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"lessThan": "47ed81aaa7f94d9808f4719e78a760c2ec1e6c86",
"versionType": "git"
},
{
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"lessThan": "48de0c6952192b0771fca468df4364d11ec74ad9",
"versionType": "git"
},
{
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"lessThan": "063497cc9f320ab71a7a937c3bc0a23e630aefe2",
"versionType": "git"
},
{
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"lessThan": "7f184ca38a90889f3f6665ff96748b95da39dbee",
"versionType": "git"
},
{
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"lessThan": "10b0ce629123a3737b4eda50188f73bb7be7b68b",
"versionType": "git"
},
{
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"lessThan": "48a69cedde7388294e4ea6fd804156cd62bc04fc",
"versionType": "git"
},
{
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"lessThan": "7c9046d92c4b9789c9d9d775e4fd5f34be64cb0a",
"versionType": "git"
},
{
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"lessThan": "dad9f96945d77ecd4708f730c06ef54dcd8cc057",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/wireless/ath/ath9k/hif_usb.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.4"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.4",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/wireless/ath/ath9k/hif_usb.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-10T13:20:28.870",
"references": [
{
"url": "https://git.kernel.org/stable/c/063497cc9f320ab71a7a937c3bc0a23e630aefe2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/10b0ce629123a3737b4eda50188f73bb7be7b68b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/47ed81aaa7f94d9808f4719e78a760c2ec1e6c86",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/48a69cedde7388294e4ea6fd804156cd62bc04fc",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/48de0c6952192b0771fca468df4364d11ec74ad9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7c9046d92c4b9789c9d9d775e4fd5f34be64cb0a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7f184ca38a90889f3f6665ff96748b95da39dbee",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/dad9f96945d77ecd4708f730c06ef54dcd8cc057",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request\n\nath9k_hif_request_firmware() re-arms an asynchronous firmware load via\nrequest_firmware_nowait(), passing hif_dev as the completion context, and\nthen still dereferences hif_dev:\n\n\tdev_info(&hif_dev->udev->dev, \"ath9k_htc: Firmware %s requested\\n\",\n\t\t hif_dev->fw_name);\n\nThe re-armed callback ath9k_hif_usb_firmware_cb() runs on the \"events\"\nworkqueue and, when the firmware is missing, walks the retry chain into\nath9k_hif_usb_firmware_fail() -> complete_all(&hif_dev->fw_done). That\nreleases the wait_for_completion(&hif_dev->fw_done) in a concurrent\nath9k_hif_usb_disconnect(), which then kfree()s hif_dev. The trailing\ndev_info() in the frame that re-armed the request can therefore read freed\nmemory (hif_dev->udev, the first field of struct hif_device_usb):\n\n BUG: KASAN: slab-use-after-free in ath9k_hif_request_firmware\n Read of size 8 ... by task kworker/...\n ath9k_hif_request_firmware\n ath9k_hif_usb_firmware_cb drivers/net/wireless/ath/ath9k/hif_usb.c:1247\n request_firmware_work_func\n Allocated by ...:\n ath9k_hif_usb_probe drivers/net/wireless/ath/ath9k/hif_usb.c\n Freed by ...:\n ath9k_hif_usb_disconnect -> kfree drivers/net/wireless/ath/ath9k/hif_usb.c\n\nThe fw_done barrier only makes disconnect wait for the firmware chain to\n*terminate*; it does not protect the outer ath9k_hif_request_firmware()\nframe that re-armed the request and keeps touching hif_dev afterwards.\n\nDrop the post-request dev_info(): it is the only use of hif_dev after the\nasync request is armed, and it is purely informational (the dev_err() on the\nfailure path runs only when request_firmware_nowait() did not arm a callback,\nso hif_dev is still alive there).\n\nThis was first reported by syzbot as a single, non-reproduced crash that was\nlater auto-obsoleted, and was independently rediscovered by the reFuzz fuzzer,\nwhich produced a C reproducer (USB-gadget connect/disconnect of an ath9k_htc\ndevice whose firmware download fails). The vulnerable code is unchanged and\nstill present in v7.1-rc6, where the slab-use-after-free reproduces under KASAN\nonce the (sub-microsecond) race window is widened."
}
],
"lastModified": "2026-08-19T17:20:45.943",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}