CVE-2022-50187
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/06/2025
Last modified:
18/06/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ath11k: fix netdev open race<br />
<br />
Make sure to allocate resources needed before registering the device.<br />
<br />
This specifically avoids having a racing open() trigger a BUG_ON() in<br />
mod_timer() when ath11k_mac_op_start() is called before the<br />
mon_reap_timer as been set up.<br />
<br />
I did not see this issue with next-20220310, but I hit it on every probe<br />
with next-20220511. Perhaps some timing changed in between.<br />
<br />
Here&#39;s the backtrace:<br />
<br />
[ 51.346947] kernel BUG at kernel/time/timer.c:990!<br />
[ 51.346958] Internal error: Oops - BUG: 0 [#1] PREEMPT SMP<br />
...<br />
[ 51.578225] Call trace:<br />
[ 51.583293] __mod_timer+0x298/0x390<br />
[ 51.589518] mod_timer+0x14/0x20<br />
[ 51.595368] ath11k_mac_op_start+0x41c/0x4a0 [ath11k]<br />
[ 51.603165] drv_start+0x38/0x60 [mac80211]<br />
[ 51.610110] ieee80211_do_open+0x29c/0x7d0 [mac80211]<br />
[ 51.617945] ieee80211_open+0x60/0xb0 [mac80211]<br />
[ 51.625311] __dev_open+0x100/0x1c0<br />
[ 51.631420] __dev_change_flags+0x194/0x210<br />
[ 51.638214] dev_change_flags+0x24/0x70<br />
[ 51.644646] do_setlink+0x228/0xdb0<br />
[ 51.650723] __rtnl_newlink+0x460/0x830<br />
[ 51.657162] rtnl_newlink+0x4c/0x80<br />
[ 51.663229] rtnetlink_rcv_msg+0x124/0x390<br />
[ 51.669917] netlink_rcv_skb+0x58/0x130<br />
[ 51.676314] rtnetlink_rcv+0x18/0x30<br />
[ 51.682460] netlink_unicast+0x250/0x310<br />
[ 51.688960] netlink_sendmsg+0x19c/0x3e0<br />
[ 51.695458] ____sys_sendmsg+0x220/0x290<br />
[ 51.701938] ___sys_sendmsg+0x7c/0xc0<br />
[ 51.708148] __sys_sendmsg+0x68/0xd0<br />
[ 51.714254] __arm64_sys_sendmsg+0x28/0x40<br />
[ 51.720900] invoke_syscall+0x48/0x120<br />
<br />
Tested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/307ce58270b3b50ca21cfcc910568429b06803f7
- https://git.kernel.org/stable/c/a2c45f8c3d18269e641f0c7da2dde47ef8414034
- https://git.kernel.org/stable/c/abb7dc8fbb27c15dcc927df56190f3c5ede58bd5
- https://git.kernel.org/stable/c/d4ba1ff87b17e81686ada8f429300876f55f95ad
- https://git.kernel.org/stable/c/eaff3946a86fc63280a30158a4ae1e141449817c