PT-2026-104999 · Azure Linux · Kernel

Publicado

2026-09-24

·

Atualizado

2026-09-24

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mld: purge async notifications upon nic error
This fixes a kernel panic in reconfig failure:
  1. we have a BSS connection
  2. we have a NAN connection
  3. FW error occurs
  4. reconfig restores the BSS connection
  5. however, restoring the NAN connection fails due to a FW error.
  6. erroneously, ieee80211 handle reconfig failure is called and marks all interfaces as not-in-driver (will be fixed in a different patch).
  7. mac80211 frees the links of the BSS connection but doesn't tell the driver about that, as it thinks that this vif is not in the driver.
  8. in ieee80211 stop device, ALL wiphy works are getting flushed (erroneously?)
  9. Therefore, async handlers wk is being executed, processing the statistics notification that was received after we restored the BSS connection.
  10. the notification handler dereferences fw id to bss conf[id], which is now a dangling pointer, as mac80211 already freed this link in (7).
  11. On the first access to one of the links fields, we panic.
While this can and should be fixed by removing the call to ieee80211 handle reconfig failure in (6), it is also not a good idea to carry and maybe handle notifications from a dead FW.
We do purge the notifications when we stop the FW, but in reconfig failure we stop the FW too late, after the notifications are processed. In addition, async handlers wk can always be scheduled before the reconfig work.
Purge the notifications immediately when transport notifies about a nic error.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

AZL-104015

Produtos afetados

Kernel