« Volver al listado

CVE-2026-74366

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath12k: fix NULL deref in change_sta_links for unready link

_ieee80211_set_active_links() calls _ieee80211_link_use_channel() for each newly-added link and WARN_ON_ONCE()s if it fails. The call uses assign_on_failure=true, which allows mac80211 to continue despite driver failures, but when a mac80211-level channel validation fails (e.g., combinations check, DFS, or no available radio), drv_assign_vif_chanctx() is never reached. Since ath12k_mac_vdev_create() is only called from that path, arvif->is_created remains false and arvif->ar remains NULL for the failed link.

Leer descripción completaMostrar menos

The subsequent drv_change_sta_links() call reaches ath12k_mac_op_change_sta_links(), which allocates an arsta and sets ahsta->links_map |= BIT(link_id) for the broken link before checking whether the link is ready. When the vdev was never created, only station_add() is skipped, but the link remains in links_map.

Any subsequent operation iterating links_map and dereferencing arvif->ar without a NULL check will crash. Two observed examples are NULL deref in ath12k_mac_ml_station_remove() on disconnect and in ath12k_mac_op_set_key() when wpa_supplicant installs PTK keys.

Fix this by checking arvif->is_created before calling ath12k_mac_alloc_assign_link_sta(). This prevents the broken link from entering links_map, so all subsequent operations iterating the bitmap are protected. The reliability of arvif->is_created across all error paths is ensured by the preceding patch.

Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c5-00302-QCAHMTSWPL_V1.0_V2.0_SILICONZ-1.115823.3

Detalles técnicos trazas, registros y código del informe original
  BUG: Unable to handle kernel NULL pointer dereference at 0x00000000
  pc : ath12k_mac_station_post_remove+0x40/0xe8 [ath12k]
  Call trace:
   ath12k_mac_station_post_remove+0x40/0xe8 [ath12k]
   ath12k_mac_op_sta_state+0xb60/0x1720 [ath12k]
   drv_sta_state+0x100/0xbd8 [mac80211]
   __sta_info_destroy_part2+0x148/0x178 [mac80211]
   ieee80211_set_disassoc+0x500/0x678 [mac80211]

  BUG: Unable to handle kernel NULL pointer dereference at 0x00000000
  pc : ath12k_mac_op_set_key+0x1f8/0x2c0 [ath12k]
  Call trace:
   ath12k_mac_op_set_key+0x1f8/0x2c0 [ath12k]
   drv_set_key+0x70/0x100 [mac80211]
   ieee80211_key_enable_hw_accel+0x78/0x260 [mac80211]
   ieee80211_add_key+0x16c/0x2ac [mac80211]
   nl80211_new_key+0x138/0x280 [cfg80211]

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74366",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "a27fa6148dacc79451e523c2694bc0a673b1be05",
              "lessThan": "cfcea221db933295bf2cd75a7f80d441c7a51e28",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a27fa6148dacc79451e523c2694bc0a673b1be05",
              "lessThan": "5f5be2aa3b6d730c51dd4f8b432f2ad72823e63f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a27fa6148dacc79451e523c2694bc0a673b1be05",
              "lessThan": "47809a7c8348bc4a332ccc26a37c7145a5f609f8",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/wireless/ath/ath12k/mac.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.14"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.14",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/wireless/ath/ath12k/mac.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:22:38.287",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/47809a7c8348bc4a332ccc26a37c7145a5f609f8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5f5be2aa3b6d730c51dd4f8b432f2ad72823e63f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cfcea221db933295bf2cd75a7f80d441c7a51e28",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath12k: fix NULL deref in change_sta_links for unready link\n\n_ieee80211_set_active_links() calls _ieee80211_link_use_channel() for\neach newly-added link and WARN_ON_ONCE()s if it fails. The call uses\nassign_on_failure=true, which allows mac80211 to continue despite\ndriver failures, but when a mac80211-level channel validation fails\n(e.g., combinations check, DFS, or no available radio),\ndrv_assign_vif_chanctx() is never reached. Since ath12k_mac_vdev_create()\nis only called from that path, arvif->is_created remains false and\narvif->ar remains NULL for the failed link.\n\nThe subsequent drv_change_sta_links() call reaches\nath12k_mac_op_change_sta_links(), which allocates an arsta and sets\nahsta->links_map |= BIT(link_id) for the broken link before checking\nwhether the link is ready. When the vdev was never created, only\nstation_add() is skipped, but the link remains in links_map.\n\nAny subsequent operation iterating links_map and dereferencing arvif->ar\nwithout a NULL check will crash. Two observed examples are NULL deref in\nath12k_mac_ml_station_remove() on disconnect and in ath12k_mac_op_set_key()\nwhen wpa_supplicant installs PTK keys.\n\n  BUG: Unable to handle kernel NULL pointer dereference at 0x00000000\n  pc : ath12k_mac_station_post_remove+0x40/0xe8 [ath12k]\n  Call trace:\n   ath12k_mac_station_post_remove+0x40/0xe8 [ath12k]\n   ath12k_mac_op_sta_state+0xb60/0x1720 [ath12k]\n   drv_sta_state+0x100/0xbd8 [mac80211]\n   __sta_info_destroy_part2+0x148/0x178 [mac80211]\n   ieee80211_set_disassoc+0x500/0x678 [mac80211]\n\n  BUG: Unable to handle kernel NULL pointer dereference at 0x00000000\n  pc : ath12k_mac_op_set_key+0x1f8/0x2c0 [ath12k]\n  Call trace:\n   ath12k_mac_op_set_key+0x1f8/0x2c0 [ath12k]\n   drv_set_key+0x70/0x100 [mac80211]\n   ieee80211_key_enable_hw_accel+0x78/0x260 [mac80211]\n   ieee80211_add_key+0x16c/0x2ac [mac80211]\n   nl80211_new_key+0x138/0x280 [cfg80211]\n\nFix this by checking arvif->is_created before calling\nath12k_mac_alloc_assign_link_sta(). This prevents the broken link from\nentering links_map, so all subsequent operations iterating the bitmap\nare protected. The reliability of arvif->is_created across all error\npaths is ensured by the preceding patch.\n\nTested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c5-00302-QCAHMTSWPL_V1.0_V2.0_SILICONZ-1.115823.3"
    }
  ],
  "lastModified": "2026-08-17T06:19:31.440",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}