PT-2026-106636 · Linux · Linux
CVE-2026-98307
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: cleanup arsta in ath11k mac peer cleanup all()
When mac80211 removes a sta, it calls .sta state() which in turn calls
ath11k mac station remove(). In that function we clean up both peers &
arsta related resources.
But when the firmware crashes, ath11k calls ieee80211 restart hw(), which
assumes that all driver related resources are cleaned up beforehand. This
cleanup is supposedly done by ath11k mac peer cleanup all() but does not
in fact free arsta->rx stats / tx stats.
Extract the arsta cleanup from ath11k mac station remove() into a
new ath11k mac station cleanup() and call it from both there and
ath11k mac peer cleanup all().
This should handle kmemleaks reports like:
unreferenced object 0xffffff801ae66400 (size 1024):
comm "hostapd", pid 1306, jiffies 4295011565
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace (crc d61c08ec):
kmemleak alloc+0x3c/0x50
kmalloc cache noprof+0x2b0/0x3e0
ath11k mac op sta state+0x1dc/0xb10
drv sta state+0xac/0x6f8
sta info insert rcu+0x314/0x5e0
sta info insert+0x14/0x38
ieee80211 add station+0x10c/0x1a0
nl80211 new station+0x3e8/0x680
genl family rcv msg doit+0xc0/0x120
genl rcv msg+0x1b4/0x258
netlink rcv skb+0x4c/0x108
genl rcv+0x38/0x60
netlink unicast+0x190/0x278
netlink sendmsg+0x15c/0x370
sys sendmsg+0x120/0x290
sys sendmsg+0x70/0xa0
Tested-on: QCN9074 hw1.0 PCI WLAN.HK.2.9.0.1-01977-QCAHKSWPL SILICONZ-1
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux