CVE-2026-80939
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2026
Last modified:
03/10/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot<br />
<br />
Since the hardware rfkill polling was introduced, arm64 platforms can<br />
panic with an asynchronous SError during warm reboot:<br />
<br />
SError Interrupt on CPU8, code 0x00000000be000011 -- SError<br />
Workqueue: events_power_efficient rfkill_poll [rfkill]<br />
rtw89_pci_ops_read8+0x94/0x160 [rtw89_pci]<br />
rtw89_core_rfkill_poll+0x50/0x1e0 [rtw89_core]<br />
rtw89_ops_rfkill_poll+0x40/0x68 [rtw89_core]<br />
ieee80211_rfkill_poll+0x3c/0x70 [mac80211]<br />
cfg80211_rfkill_poll+0x40/0x2a0 [cfg80211]<br />
rfkill_poll+0x30/0x88 [rfkill]<br />
Kernel panic - not syncing: Asynchronous SError Interrupt<br />
<br />
On the reboot path the kernel only runs device_shutdown(), which calls<br />
each driver&#39;s .shutdown callback; .remove is not invoked. The rtw89 PCI<br />
driver had no .shutdown callback, so nothing stopped the rfkill polling<br />
work while the platform was tearing the PCIe link down. Once the link<br />
is gone, the next MMIO read from the poll handler targets a<br />
non-responding device and is reported as a fatal asynchronous SError on<br />
arm64.<br />
<br />
Add rtw89_pci_shutdown(), wired to all rtw89 PCI device drivers, which<br />
sets a new RTW89_FLAG_SHUTDOWN flag (mirroring the USB<br />
RTW89_FLAG_UNPLUGGED pattern). When the flag is set,<br />
rtw89_ops_rfkill_poll() returns early, so no MMIO read is issued to the<br />
chip after shutdown begins and the SError no longer occurs.<br />
<br />
This does not call the full .remove path from .shutdown, to keep the<br />
shutdown handler minimal and avoid running the non-idempotent teardown<br />
twice.


