{"api_version":"1","generated_at":"2026-08-12T02:25:39+00:00","cve":"CVE-2026-68363","urls":{"html":"https://cve.report/CVE-2026-68363","api":"https://cve.report/api/cve/CVE-2026-68363.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-68363","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-68363"},"summary":{"title":"wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request\n\nath9k_hif_request_firmware() re-arms an asynchronous firmware load via\nrequest_firmware_nowait(), passing hif_dev as the completion context, and\nthen still dereferences hif_dev:\n\n\tdev_info(&hif_dev->udev->dev, \"ath9k_htc: Firmware %s requested\\n\",\n\t\t hif_dev->fw_name);\n\nThe re-armed callback ath9k_hif_usb_firmware_cb() runs on the \"events\"\nworkqueue and, when the firmware is missing, walks the retry chain into\nath9k_hif_usb_firmware_fail() -> complete_all(&hif_dev->fw_done). That\nreleases the wait_for_completion(&hif_dev->fw_done) in a concurrent\nath9k_hif_usb_disconnect(), which then kfree()s hif_dev. The trailing\ndev_info() in the frame that re-armed the request can therefore read freed\nmemory (hif_dev->udev, the first field of struct hif_device_usb):\n\n  BUG: KASAN: slab-use-after-free in ath9k_hif_request_firmware\n  Read of size 8 ... by task kworker/...\n   ath9k_hif_request_firmware\n   ath9k_hif_usb_firmware_cb           drivers/net/wireless/ath/ath9k/hif_usb.c:1247\n   request_firmware_work_func\n  Allocated by ...:\n   ath9k_hif_usb_probe                 drivers/net/wireless/ath/ath9k/hif_usb.c\n  Freed by ...:\n   ath9k_hif_usb_disconnect -> kfree   drivers/net/wireless/ath/ath9k/hif_usb.c\n\nThe fw_done barrier only makes disconnect wait for the firmware chain to\n*terminate*; it does not protect the outer ath9k_hif_request_firmware()\nframe that re-armed the request and keeps touching hif_dev afterwards.\n\nDrop the post-request dev_info(): it is the only use of hif_dev after the\nasync request is armed, and it is purely informational (the dev_err() on the\nfailure path runs only when request_firmware_nowait() did not arm a callback,\nso hif_dev is still alive there).\n\nThis was first reported by syzbot as a single, non-reproduced crash that was\nlater auto-obsoleted, and was independently rediscovered by the reFuzz fuzzer,\nwhich produced a C reproducer (USB-gadget connect/disconnect of an ath9k_htc\ndevice whose firmware download fails). The vulnerable code is unchanged and\nstill present in v7.1-rc6, where the slab-use-after-free reproduces under KASAN\nonce the (sub-microsecond) race window is widened.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-10 13:20:28","updated_at":"2026-08-10 13:20:28"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/7f184ca38a90889f3f6665ff96748b95da39dbee","name":"https://git.kernel.org/stable/c/7f184ca38a90889f3f6665ff96748b95da39dbee","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/48a69cedde7388294e4ea6fd804156cd62bc04fc","name":"https://git.kernel.org/stable/c/48a69cedde7388294e4ea6fd804156cd62bc04fc","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/dad9f96945d77ecd4708f730c06ef54dcd8cc057","name":"https://git.kernel.org/stable/c/dad9f96945d77ecd4708f730c06ef54dcd8cc057","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/7c9046d92c4b9789c9d9d775e4fd5f34be64cb0a","name":"https://git.kernel.org/stable/c/7c9046d92c4b9789c9d9d775e4fd5f34be64cb0a","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/10b0ce629123a3737b4eda50188f73bb7be7b68b","name":"https://git.kernel.org/stable/c/10b0ce629123a3737b4eda50188f73bb7be7b68b","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-68363","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68363","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e904cf6fe23022cde4e0ea9d41601411a315a3dc 7f184ca38a90889f3f6665ff96748b95da39dbee git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e904cf6fe23022cde4e0ea9d41601411a315a3dc 10b0ce629123a3737b4eda50188f73bb7be7b68b git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e904cf6fe23022cde4e0ea9d41601411a315a3dc 48a69cedde7388294e4ea6fd804156cd62bc04fc git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e904cf6fe23022cde4e0ea9d41601411a315a3dc 7c9046d92c4b9789c9d9d775e4fd5f34be64cb0a git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e904cf6fe23022cde4e0ea9d41601411a315a3dc dad9f96945d77ecd4708f730c06ef54dcd8cc057 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.4","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 4.4 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.148 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.101 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.42 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.6 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2-rc5 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/net/wireless/ath/ath9k/hif_usb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"7f184ca38a90889f3f6665ff96748b95da39dbee","status":"affected","version":"e904cf6fe23022cde4e0ea9d41601411a315a3dc","versionType":"git"},{"lessThan":"10b0ce629123a3737b4eda50188f73bb7be7b68b","status":"affected","version":"e904cf6fe23022cde4e0ea9d41601411a315a3dc","versionType":"git"},{"lessThan":"48a69cedde7388294e4ea6fd804156cd62bc04fc","status":"affected","version":"e904cf6fe23022cde4e0ea9d41601411a315a3dc","versionType":"git"},{"lessThan":"7c9046d92c4b9789c9d9d775e4fd5f34be64cb0a","status":"affected","version":"e904cf6fe23022cde4e0ea9d41601411a315a3dc","versionType":"git"},{"lessThan":"dad9f96945d77ecd4708f730c06ef54dcd8cc057","status":"affected","version":"e904cf6fe23022cde4e0ea9d41601411a315a3dc","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/net/wireless/ath/ath9k/hif_usb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"4.4"},{"lessThan":"4.4","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.148","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.101","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.42","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2-rc5","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.148","versionStartIncluding":"4.4","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.101","versionStartIncluding":"4.4","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.42","versionStartIncluding":"4.4","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.6","versionStartIncluding":"4.4","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2-rc5","versionStartIncluding":"4.4","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request\n\nath9k_hif_request_firmware() re-arms an asynchronous firmware load via\nrequest_firmware_nowait(), passing hif_dev as the completion context, and\nthen still dereferences hif_dev:\n\n\tdev_info(&hif_dev->udev->dev, \"ath9k_htc: Firmware %s requested\\n\",\n\t\t hif_dev->fw_name);\n\nThe re-armed callback ath9k_hif_usb_firmware_cb() runs on the \"events\"\nworkqueue and, when the firmware is missing, walks the retry chain into\nath9k_hif_usb_firmware_fail() -> complete_all(&hif_dev->fw_done). That\nreleases the wait_for_completion(&hif_dev->fw_done) in a concurrent\nath9k_hif_usb_disconnect(), which then kfree()s hif_dev. The trailing\ndev_info() in the frame that re-armed the request can therefore read freed\nmemory (hif_dev->udev, the first field of struct hif_device_usb):\n\n  BUG: KASAN: slab-use-after-free in ath9k_hif_request_firmware\n  Read of size 8 ... by task kworker/...\n   ath9k_hif_request_firmware\n   ath9k_hif_usb_firmware_cb           drivers/net/wireless/ath/ath9k/hif_usb.c:1247\n   request_firmware_work_func\n  Allocated by ...:\n   ath9k_hif_usb_probe                 drivers/net/wireless/ath/ath9k/hif_usb.c\n  Freed by ...:\n   ath9k_hif_usb_disconnect -> kfree   drivers/net/wireless/ath/ath9k/hif_usb.c\n\nThe fw_done barrier only makes disconnect wait for the firmware chain to\n*terminate*; it does not protect the outer ath9k_hif_request_firmware()\nframe that re-armed the request and keeps touching hif_dev afterwards.\n\nDrop the post-request dev_info(): it is the only use of hif_dev after the\nasync request is armed, and it is purely informational (the dev_err() on the\nfailure path runs only when request_firmware_nowait() did not arm a callback,\nso hif_dev is still alive there).\n\nThis was first reported by syzbot as a single, non-reproduced crash that was\nlater auto-obsoleted, and was independently rediscovered by the reFuzz fuzzer,\nwhich produced a C reproducer (USB-gadget connect/disconnect of an ath9k_htc\ndevice whose firmware download fails). The vulnerable code is unchanged and\nstill present in v7.1-rc6, where the slab-use-after-free reproduces under KASAN\nonce the (sub-microsecond) race window is widened."}],"providerMetadata":{"dateUpdated":"2026-08-10T12:03:40.355Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/7f184ca38a90889f3f6665ff96748b95da39dbee"},{"url":"https://git.kernel.org/stable/c/10b0ce629123a3737b4eda50188f73bb7be7b68b"},{"url":"https://git.kernel.org/stable/c/48a69cedde7388294e4ea6fd804156cd62bc04fc"},{"url":"https://git.kernel.org/stable/c/7c9046d92c4b9789c9d9d775e4fd5f34be64cb0a"},{"url":"https://git.kernel.org/stable/c/dad9f96945d77ecd4708f730c06ef54dcd8cc057"}],"title":"wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-68363","datePublished":"2026-08-10T12:03:40.355Z","dateReserved":"2026-07-30T09:28:09.385Z","dateUpdated":"2026-08-10T12:03:40.355Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-10 13:20:28","lastModifiedDate":"2026-08-10 13:20:28","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"68363","Ordinal":"1","Title":"wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming ","CVE":"CVE-2026-68363","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"68363","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request\n\nath9k_hif_request_firmware() re-arms an asynchronous firmware load via\nrequest_firmware_nowait(), passing hif_dev as the completion context, and\nthen still dereferences hif_dev:\n\n\tdev_info(&hif_dev->udev->dev, \"ath9k_htc: Firmware %s requested\\n\",\n\t\t hif_dev->fw_name);\n\nThe re-armed callback ath9k_hif_usb_firmware_cb() runs on the \"events\"\nworkqueue and, when the firmware is missing, walks the retry chain into\nath9k_hif_usb_firmware_fail() -> complete_all(&hif_dev->fw_done). That\nreleases the wait_for_completion(&hif_dev->fw_done) in a concurrent\nath9k_hif_usb_disconnect(), which then kfree()s hif_dev. The trailing\ndev_info() in the frame that re-armed the request can therefore read freed\nmemory (hif_dev->udev, the first field of struct hif_device_usb):\n\n  BUG: KASAN: slab-use-after-free in ath9k_hif_request_firmware\n  Read of size 8 ... by task kworker/...\n   ath9k_hif_request_firmware\n   ath9k_hif_usb_firmware_cb           drivers/net/wireless/ath/ath9k/hif_usb.c:1247\n   request_firmware_work_func\n  Allocated by ...:\n   ath9k_hif_usb_probe                 drivers/net/wireless/ath/ath9k/hif_usb.c\n  Freed by ...:\n   ath9k_hif_usb_disconnect -> kfree   drivers/net/wireless/ath/ath9k/hif_usb.c\n\nThe fw_done barrier only makes disconnect wait for the firmware chain to\n*terminate*; it does not protect the outer ath9k_hif_request_firmware()\nframe that re-armed the request and keeps touching hif_dev afterwards.\n\nDrop the post-request dev_info(): it is the only use of hif_dev after the\nasync request is armed, and it is purely informational (the dev_err() on the\nfailure path runs only when request_firmware_nowait() did not arm a callback,\nso hif_dev is still alive there).\n\nThis was first reported by syzbot as a single, non-reproduced crash that was\nlater auto-obsoleted, and was independently rediscovered by the reFuzz fuzzer,\nwhich produced a C reproducer (USB-gadget connect/disconnect of an ath9k_htc\ndevice whose firmware download fails). The vulnerable code is unchanged and\nstill present in v7.1-rc6, where the slab-use-after-free reproduces under KASAN\nonce the (sub-microsecond) race window is widened.","Type":"Description","Title":"wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming "}]}}}