wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock
Summary
| CVE | CVE-2026-68408 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-10 13:20:34 UTC |
| Updated | 2026-08-10 13:20:34 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock
When a netlink socket that owns a PMSR session is closed,
cfg80211_release_pmsr() clears the request's nl_portid and queues
pmsr_free_wk to call cfg80211_pmsr_process_abort() asynchronously.
If the interface tears down concurrently, cfg80211_pmsr_wdev_down()
is called under wiphy_lock and calls cancel_work_sync(&pmsr_free_wk)
to wait for any running work. The work function acquires wiphy_lock
via guard(wiphy) before calling process_abort.
This is a deadlock: wdev_down holds wiphy_lock and blocks inside
cancel_work_sync(); pmsr_free_wk blocks trying to acquire that same
wiphy_lock. Neither thread can proceed.
The same deadlock is reachable from cfg80211_leave_locked(), which
calls cfg80211_pmsr_wdev_down() for all interface types under
wiphy_lock.
Fix this by converting pmsr_free_wk from a plain work_struct to a
wiphy_work. The wiphy_work dispatcher holds wiphy_lock when running
work items, so the explicit guard(wiphy) in the work function is no
longer needed. wiphy_work_cancel() can be called safely while holding
wiphy_lock - since wiphy_lock prevents the work from running
concurrently, wiphy_work_cancel() never blocks, eliminating the
deadlock.
Remove the cancel_work_sync() for pmsr_free_wk from the
NETDEV_GOING_DOWN handler. cfg80211_leave(), called unconditionally
just before it, already cancels any pending work under wiphy_lock
via wiphy_work_cancel() inside cfg80211_pmsr_wdev_down(). |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected d32c07ef1880fe20cf4ab223dbfedc9c0b2816aa 21512b5f7a74fd18c996c22e6854efe57d570816 git |
Not specified |
| CNA |
Linux |
Linux |
affected a1b7a843f12a0c3e9d3a2ca607ce451916ef42cf 133684982dd0c24359fcc641d19d89cc17d6e5ef git |
Not specified |
| CNA |
Linux |
Linux |
affected 6dccbc9f3e1d38565dff7730d2b7d1e8b16c9b09 0a77d9fb4d5c0e01306cd406ffdee8f1fe955c0e git |
Not specified |
| CNA |
Linux |
Linux |
affected 6dccbc9f3e1d38565dff7730d2b7d1e8b16c9b09 2b0eab425e1f658d8fe1df7590e3b9af5959505e git |
Not specified |
| CNA |
Linux |
Linux |
affected 28d3551f8d8cb3aec7497894d94150fe84d20e5e git |
Not specified |
| CNA |
Linux |
Linux |
affected 37e776e2e0a523731e2470dce6d563f0e8632a40 git |
Not specified |
| CNA |
Linux |
Linux |
affected 72b7ea786b8e570ae11149e9089859a4a8634a13 git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.12.78 6.12.101 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.18.20 6.18.42 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.1.167 6.2 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.6.130 6.7 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.19.10 6.20 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 7.0 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.0 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.101 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.42 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.6 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc4 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/21512b5f7a74fd18c996c22e6854efe57d570816 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/2b0eab425e1f658d8fe1df7590e3b9af5959505e |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/0a77d9fb4d5c0e01306cd406ffdee8f1fe955c0e |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/133684982dd0c24359fcc641d19d89cc17d6e5ef |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.