« Volver al listado

CVE-2026-98307

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath11k: cleanup arsta in ath11k_mac_peer_cleanup_all()

When mac80211 removes a sta, it calls .sta_state() which in turn calls ath11k_mac_station_remove(). In that function we clean up both peers & arsta related resources.

But when the firmware crashes, ath11k calls ieee80211_restart_hw(), which assumes that all driver related resources are cleaned up beforehand. This cleanup is supposedly done by ath11k_mac_peer_cleanup_all() but does not in fact free arsta->rx_stats / tx_stats.

Extract the arsta cleanup from ath11k_mac_station_remove() into a new ath11k_mac_station_cleanup() and call it from both there and ath11k_mac_peer_cleanup_all().

Leer descripción completaMostrar menos

Tested-on: QCN9074 hw1.0 PCI WLAN.HK.2.9.0.1-01977-QCAHKSWPL_SILICONZ-1

Detalles técnicos trazas, registros y código del informe original
This should handle kmemleaks reports like:
	unreferenced object 0xffffff801ae66400 (size 1024):
	  comm "hostapd", pid 1306, jiffies 4295011565
	  hex dump (first 32 bytes):
	    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
	    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
	  backtrace (crc d61c08ec):
	    kmemleak_alloc+0x3c/0x50
	    __kmalloc_cache_noprof+0x2b0/0x3e0
	    ath11k_mac_op_sta_state+0x1dc/0xb10
	    drv_sta_state+0xac/0x6f8
	    sta_info_insert_rcu+0x314/0x5e0
	    sta_info_insert+0x14/0x38
	    ieee80211_add_station+0x10c/0x1a0
	    nl80211_new_station+0x3e8/0x680
	    genl_family_rcv_msg_doit+0xc0/0x120
	    genl_rcv_msg+0x1b4/0x258
	    netlink_rcv_skb+0x4c/0x108
	    genl_rcv+0x38/0x60
	    netlink_unicast+0x190/0x278
	    netlink_sendmsg+0x15c/0x370
	    ____sys_sendmsg+0x120/0x290
	    ___sys_sendmsg+0x70/0xa0

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98307",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "d5c65159f2895379e11ca13f62feabe93278985d",
              "lessThan": "c4108dce0838ec7d38d782f76f9c007cfe2fff45",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d5c65159f2895379e11ca13f62feabe93278985d",
              "lessThan": "57bc3cd46458eafa1c38e3044a61b7399cde7642",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d5c65159f2895379e11ca13f62feabe93278985d",
              "lessThan": "be1d5e95ec499ed5ee9704aa27dd1407ccf0d0ac",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d5c65159f2895379e11ca13f62feabe93278985d",
              "lessThan": "820b8cff81c796ba20573e04722ab62500713f97",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/wireless/ath/ath11k/mac.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.6"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.6",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/wireless/ath/ath11k/mac.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:21.950",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/57bc3cd46458eafa1c38e3044a61b7399cde7642",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/820b8cff81c796ba20573e04722ab62500713f97",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/be1d5e95ec499ed5ee9704aa27dd1407ccf0d0ac",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c4108dce0838ec7d38d782f76f9c007cfe2fff45",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: cleanup arsta in ath11k_mac_peer_cleanup_all()\n\nWhen mac80211 removes a sta, it calls .sta_state() which in turn calls\nath11k_mac_station_remove(). In that function we clean up both peers &\narsta related resources.\n\nBut when the firmware crashes, ath11k calls ieee80211_restart_hw(), which\nassumes that all driver related resources are cleaned up beforehand. This\ncleanup is supposedly done by ath11k_mac_peer_cleanup_all() but does not\nin fact free arsta->rx_stats / tx_stats.\n\nExtract the arsta cleanup from ath11k_mac_station_remove() into a\nnew ath11k_mac_station_cleanup() and call it from both there and\nath11k_mac_peer_cleanup_all().\n\nThis should handle kmemleaks reports like:\n\tunreferenced object 0xffffff801ae66400 (size 1024):\n\t  comm \"hostapd\", pid 1306, jiffies 4295011565\n\t  hex dump (first 32 bytes):\n\t    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................\n\t    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................\n\t  backtrace (crc d61c08ec):\n\t    kmemleak_alloc+0x3c/0x50\n\t    __kmalloc_cache_noprof+0x2b0/0x3e0\n\t    ath11k_mac_op_sta_state+0x1dc/0xb10\n\t    drv_sta_state+0xac/0x6f8\n\t    sta_info_insert_rcu+0x314/0x5e0\n\t    sta_info_insert+0x14/0x38\n\t    ieee80211_add_station+0x10c/0x1a0\n\t    nl80211_new_station+0x3e8/0x680\n\t    genl_family_rcv_msg_doit+0xc0/0x120\n\t    genl_rcv_msg+0x1b4/0x258\n\t    netlink_rcv_skb+0x4c/0x108\n\t    genl_rcv+0x38/0x60\n\t    netlink_unicast+0x190/0x278\n\t    netlink_sendmsg+0x15c/0x370\n\t    ____sys_sendmsg+0x120/0x290\n\t    ___sys_sendmsg+0x70/0xa0\n\nTested-on: QCN9074 hw1.0 PCI WLAN.HK.2.9.0.1-01977-QCAHKSWPL_SILICONZ-1"
    }
  ],
  "lastModified": "2026-10-06T09:18:21.950",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}