CVE-2026-68362

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/08/2026
Last modified:
19/08/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin<br /> <br /> In ATH11K_QMI_EVENT_FW_READY, ATH11K_FLAG_REGISTERED is set<br /> unconditionally even when ath11k_core_qmi_firmware_ready() fails.<br /> This leaves the driver in an inconsistent state where<br /> initialization is considered complete although the firmware ready<br /> handling did not finish successfully. During the subsequent SSR,<br /> the driver enters the restart path based on this incorrect state<br /> and dereferences uninitialized srng members, resulting in a NULL<br /> pointer dereference.<br /> <br /> Call trace:<br /> ath11k_hal_srng_access_begin+0xc/0x60 [ath11k] (P)<br /> ath11k_ce_cleanup_pipes+0x17c/0x180 [ath11k]<br /> ath11k_core_restart+0x40/0x168 [ath11k]<br /> <br /> Fix this by:<br /> - skipping firmware_ready if ATH11K_FLAG_REGISTERED is already set<br /> - setting ATH11K_FLAG_REGISTERED only when firmware_ready succeeds<br /> - setting ATH11K_FLAG_QMI_FAIL and aborting the FW_READY handling<br /> on error<br /> <br /> Tested-on: WCN6750 hw1.0 AHB WLAN.MSL.2.0.c2-00204-QCAMSLSWPLZ-1

Impact