PT-2026-106636 · Linux · Linux

CVE-2026-98307

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: cleanup arsta in ath11k mac peer cleanup all()
When mac80211 removes a sta, it calls .sta state() which in turn calls ath11k mac station remove(). In that function we clean up both peers & arsta related resources.
But when the firmware crashes, ath11k calls ieee80211 restart hw(), which assumes that all driver related resources are cleaned up beforehand. This cleanup is supposedly done by ath11k mac peer cleanup all() but does not in fact free arsta->rx stats / tx stats.
Extract the arsta cleanup from ath11k mac station remove() into a new ath11k mac station cleanup() and call it from both there and ath11k mac peer cleanup all().
This should handle kmemleaks reports like: unreferenced object 0xffffff801ae66400 (size 1024): comm "hostapd", pid 1306, jiffies 4295011565 hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace (crc d61c08ec): kmemleak alloc+0x3c/0x50 kmalloc cache noprof+0x2b0/0x3e0 ath11k mac op sta state+0x1dc/0xb10 drv sta state+0xac/0x6f8 sta info insert rcu+0x314/0x5e0 sta info insert+0x14/0x38 ieee80211 add station+0x10c/0x1a0 nl80211 new station+0x3e8/0x680 genl family rcv msg doit+0xc0/0x120 genl rcv msg+0x1b4/0x258 netlink rcv skb+0x4c/0x108 genl rcv+0x38/0x60 netlink unicast+0x190/0x278 netlink sendmsg+0x15c/0x370 sys sendmsg+0x120/0x290 sys sendmsg+0x70/0xa0
Tested-on: QCN9074 hw1.0 PCI WLAN.HK.2.9.0.1-01977-QCAHKSWPL SILICONZ-1
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98307

Affected Products

Linux