CVE-2026-68362
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/08/2026
Last modified:
19/08/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin<br />
<br />
In ATH11K_QMI_EVENT_FW_READY, ATH11K_FLAG_REGISTERED is set<br />
unconditionally even when ath11k_core_qmi_firmware_ready() fails.<br />
This leaves the driver in an inconsistent state where<br />
initialization is considered complete although the firmware ready<br />
handling did not finish successfully. During the subsequent SSR,<br />
the driver enters the restart path based on this incorrect state<br />
and dereferences uninitialized srng members, resulting in a NULL<br />
pointer dereference.<br />
<br />
Call trace:<br />
ath11k_hal_srng_access_begin+0xc/0x60 [ath11k] (P)<br />
ath11k_ce_cleanup_pipes+0x17c/0x180 [ath11k]<br />
ath11k_core_restart+0x40/0x168 [ath11k]<br />
<br />
Fix this by:<br />
- skipping firmware_ready if ATH11K_FLAG_REGISTERED is already set<br />
- setting ATH11K_FLAG_REGISTERED only when firmware_ready succeeds<br />
- setting ATH11K_FLAG_QMI_FAIL and aborting the FW_READY handling<br />
on error<br />
<br />
Tested-on: WCN6750 hw1.0 AHB WLAN.MSL.2.0.c2-00204-QCAMSLSWPLZ-1
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/4abb4e284d8897176e91d7a3168ee29ed876bb41
- https://git.kernel.org/stable/c/66bf998b18334ca97321433e4ab783b6ff267e9d
- https://git.kernel.org/stable/c/d6bba659ac30d862ee7bab92862cd6e514f07521
- https://git.kernel.org/stable/c/e517e207300edcf7f3a8f6c45f9155c0e419ffb9
- https://git.kernel.org/stable/c/e5394605f9a985cc3a8263e610ba84b33cbe7b0c
- https://git.kernel.org/stable/c/e8d85672dd7e2523f774caafba8f858384e18df7



