-

CVE-2026-68363

wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request

ath9k_hif_request_firmware() re-arms an asynchronous firmware load via
request_firmware_nowait(), passing hif_dev as the completion context, and
then still dereferences hif_dev:

	dev_info(&hif_dev->udev->dev, "ath9k_htc: Firmware %s requested\n",
		 hif_dev->fw_name);

The re-armed callback ath9k_hif_usb_firmware_cb() runs on the "events"
workqueue and, when the firmware is missing, walks the retry chain into
ath9k_hif_usb_firmware_fail() -> complete_all(&hif_dev->fw_done). That
releases the wait_for_completion(&hif_dev->fw_done) in a concurrent
ath9k_hif_usb_disconnect(), which then kfree()s hif_dev. The trailing
dev_info() in the frame that re-armed the request can therefore read freed
memory (hif_dev->udev, the first field of struct hif_device_usb):

  BUG: KASAN: slab-use-after-free in ath9k_hif_request_firmware
  Read of size 8 ... by task kworker/...
   ath9k_hif_request_firmware
   ath9k_hif_usb_firmware_cb           drivers/net/wireless/ath/ath9k/hif_usb.c:1247
   request_firmware_work_func
  Allocated by ...:
   ath9k_hif_usb_probe                 drivers/net/wireless/ath/ath9k/hif_usb.c
  Freed by ...:
   ath9k_hif_usb_disconnect -> kfree   drivers/net/wireless/ath/ath9k/hif_usb.c

The fw_done barrier only makes disconnect wait for the firmware chain to
*terminate*; it does not protect the outer ath9k_hif_request_firmware()
frame that re-armed the request and keeps touching hif_dev afterwards.

Drop the post-request dev_info(): it is the only use of hif_dev after the
async request is armed, and it is purely informational (the dev_err() on the
failure path runs only when request_firmware_nowait() did not arm a callback,
so hif_dev is still alive there).

This was first reported by syzbot as a single, non-reproduced crash that was
later auto-obsoleted, and was independently rediscovered by the reFuzz fuzzer,
which produced a C reproducer (USB-gadget connect/disconnect of an ath9k_htc
device whose firmware download fails). The vulnerable code is unchanged and
still present in v7.1-rc6, where the slab-use-after-free reproduces under KASAN
once the (sub-microsecond) race window is widened.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version e904cf6fe23022cde4e0ea9d41601411a315a3dc
Version < 47ed81aaa7f94d9808f4719e78a760c2ec1e6c86
Status affected
Version e904cf6fe23022cde4e0ea9d41601411a315a3dc
Version < 48de0c6952192b0771fca468df4364d11ec74ad9
Status affected
Version e904cf6fe23022cde4e0ea9d41601411a315a3dc
Version < 063497cc9f320ab71a7a937c3bc0a23e630aefe2
Status affected
Version e904cf6fe23022cde4e0ea9d41601411a315a3dc
Version < 7f184ca38a90889f3f6665ff96748b95da39dbee
Status affected
Version e904cf6fe23022cde4e0ea9d41601411a315a3dc
Version < 10b0ce629123a3737b4eda50188f73bb7be7b68b
Status affected
Version e904cf6fe23022cde4e0ea9d41601411a315a3dc
Version < 48a69cedde7388294e4ea6fd804156cd62bc04fc
Status affected
Version e904cf6fe23022cde4e0ea9d41601411a315a3dc
Version < 7c9046d92c4b9789c9d9d775e4fd5f34be64cb0a
Status affected
Version e904cf6fe23022cde4e0ea9d41601411a315a3dc
Version < dad9f96945d77ecd4708f730c06ef54dcd8cc057
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.4
Status affected
Version 0
Version < 4.4
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.083
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/7f184ca38a90889f3f6665ff96748b95da39dbee
https://git.kernel.org/stable/c/10b0ce629123a3737b4eda50188f73bb7be7b68b
https://git.kernel.org/stable/c/48a69cedde7388294e4ea6fd804156cd62bc04fc
https://git.kernel.org/stable/c/7c9046d92c4b9789c9d9d775e4fd5f34be64cb0a
https://git.kernel.org/stable/c/dad9f96945d77ecd4708f730c06ef54dcd8cc057
https://git.kernel.org/stable/c/063497cc9f320ab71a7a937c3bc0a23e630aefe2
https://git.kernel.org/stable/c/47ed81aaa7f94d9808f4719e78a760c2ec1e6c86
https://git.kernel.org/stable/c/48de0c6952192b0771fca468df4364d11ec74ad9