Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-80939

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/09/2026
Última modificación:
03/10/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot<br /> <br /> Since the hardware rfkill polling was introduced, arm64 platforms can<br /> panic with an asynchronous SError during warm reboot:<br /> <br /> SError Interrupt on CPU8, code 0x00000000be000011 -- SError<br /> Workqueue: events_power_efficient rfkill_poll [rfkill]<br /> rtw89_pci_ops_read8+0x94/0x160 [rtw89_pci]<br /> rtw89_core_rfkill_poll+0x50/0x1e0 [rtw89_core]<br /> rtw89_ops_rfkill_poll+0x40/0x68 [rtw89_core]<br /> ieee80211_rfkill_poll+0x3c/0x70 [mac80211]<br /> cfg80211_rfkill_poll+0x40/0x2a0 [cfg80211]<br /> rfkill_poll+0x30/0x88 [rfkill]<br /> Kernel panic - not syncing: Asynchronous SError Interrupt<br /> <br /> On the reboot path the kernel only runs device_shutdown(), which calls<br /> each driver&amp;#39;s .shutdown callback; .remove is not invoked. The rtw89 PCI<br /> driver had no .shutdown callback, so nothing stopped the rfkill polling<br /> work while the platform was tearing the PCIe link down. Once the link<br /> is gone, the next MMIO read from the poll handler targets a<br /> non-responding device and is reported as a fatal asynchronous SError on<br /> arm64.<br /> <br /> Add rtw89_pci_shutdown(), wired to all rtw89 PCI device drivers, which<br /> sets a new RTW89_FLAG_SHUTDOWN flag (mirroring the USB<br /> RTW89_FLAG_UNPLUGGED pattern). When the flag is set,<br /> rtw89_ops_rfkill_poll() returns early, so no MMIO read is issued to the<br /> chip after shutdown begins and the SError no longer occurs.<br /> <br /> This does not call the full .remove path from .shutdown, to keep the<br /> shutdown handler minimal and avoid running the non-idempotent teardown<br /> twice.

Impacto