{"api_version":"1","generated_at":"2026-08-16T20:16:50+00:00","cve":"CVE-2026-68469","urls":{"html":"https://cve.report/CVE-2026-68469","api":"https://cve.report/api/cve/CVE-2026-68469.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-68469","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-68469"},"summary":{"title":"wifi: mwifiex: fix permanently busy scans after multiple roam iterations","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: fix permanently busy scans after multiple roam iterations\n\nIn order for the firmware to sleep, the driver has to confirm a\npreviously received sleep request. The normal sequence of evets goes\nlike this:\nEVENT_SLEEP -> adapter->ps_state = PS_STATE_PRE_SLEEP -> sleep-confirm\n-> SLEEP -> EVENT_AWAKE -> AWAKE.\nBefore sending the sleep-confirm command, the driver must make sure\nthere are no commands either running or waiting to be completed.\n\nmwifiex_ret_802_11_associate() unconditionally sets\nps_state = PS_STATE_AWAKE when it processes the association command\nresponse, outside of the normal powersave management flow. If\nEVENT_SLEEP arrives while the association command is in flight,\nps_state is PRE_SLEEP when the association command response is parsed,\nand the forced AWAKE overwrites it. The deferred sleep-confirm is\nnever sent.\n\nA subsequent scan_start command is correctly acknowledged, but the\nfirmware doesn't generate scan_result events. The scan request never\nfinishes, and additional requests from userspace fail with -EBUSY.\n\nAfter testing on both IW412 and W8997, I could only trigger the bug on\nthe IW412 and observed the firmwares behave differently. On the IW412\nthe firmware still sends EVENT_SLEEP while the authentication /\nassociation process is ongoing. A W8997 under the same\nconditions seems to suppress power-save for the duration of the\nassociation, so PRE_SLEEP never coincided with the association response\neven after extended periods of testing using the loops\ndescribed below (>12hours).\n\nOn the IW412, the delay between commands that triggers an EVENT_SLEEP\nwas empirically determined to be ~20ms. This delay can naturally occur\nwhen the driver is outputting debugging information\n(debug_mask = 0x00000037), in which situation the busy scans issue is\nrepeatable while running \"test 1)\" as described below. If the delay\nbetween commands is less than ~20ms, the firmware stays awake and\nthe issue was not reproducible running the same test.\n\nThe host_mlme=false path also behaves differently. In this case, the\nentire authentication / association transaction is executed by one\ncommand (HostCmd_CMD_802_11_ASSOCIATE), and the firmware doesn't emit\nEVENT_SLEEP while the command is running.\n\nRemove the assignment so the ps_state is only manipulated in the paths\nthat are related to powersave event handling and on the main workqueue\nfor correct sleep confirmation.\n\nThe following loop tests were performed (with debugging output enabled):\n1) force roaming between two AP's, one 5GHz and one 2.4GHz, same\nSSID. Use wpa_cli to trigger the roaming behavior, sleep 2s\nbetween iterations.\n2) force a disconnection to AP 1 and a connection to AP 2, test\nscan. Use wpa_cli to trigger the connection changes, sleep 2s\nbetween iterations.\n\nEach test ran in each device for at least 3 hours.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-15 06:19:57","updated_at":"2026-08-15 06:19:57"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/a59cfa165aee3e29d06145041c0ebe46a51de604","name":"https://git.kernel.org/stable/c/a59cfa165aee3e29d06145041c0ebe46a51de604","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/d78a407bad6f500884a8606aea1a5a9207be4030","name":"https://git.kernel.org/stable/c/d78a407bad6f500884a8606aea1a5a9207be4030","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/deb5f0ae384f1cf41fccaf6375266db2f2911b2b","name":"https://git.kernel.org/stable/c/deb5f0ae384f1cf41fccaf6375266db2f2911b2b","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/1bc55db2d34756bd53e4460dbb699619ee13cd7f","name":"https://git.kernel.org/stable/c/1bc55db2d34756bd53e4460dbb699619ee13cd7f","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/6126e12bf8c87badeab41a164c9689ac88e5c160","name":"https://git.kernel.org/stable/c/6126e12bf8c87badeab41a164c9689ac88e5c160","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/31a2c409f8f58d20f0f6391c151421155768ed77","name":"https://git.kernel.org/stable/c/31a2c409f8f58d20f0f6391c151421155768ed77","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/2ed36b2586f16c480ed58de303af704c2235e16d","name":"https://git.kernel.org/stable/c/2ed36b2586f16c480ed58de303af704c2235e16d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/5796eabe435d83544b6fe39851ce47ca68fdb778","name":"https://git.kernel.org/stable/c/5796eabe435d83544b6fe39851ce47ca68fdb778","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-68469","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68469","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e 2ed36b2586f16c480ed58de303af704c2235e16d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e 5796eabe435d83544b6fe39851ce47ca68fdb778 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e 31a2c409f8f58d20f0f6391c151421155768ed77 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e deb5f0ae384f1cf41fccaf6375266db2f2911b2b git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e 1bc55db2d34756bd53e4460dbb699619ee13cd7f git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e a59cfa165aee3e29d06145041c0ebe46a51de604 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e 6126e12bf8c87badeab41a164c9689ac88e5c160 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e d78a407bad6f500884a8606aea1a5a9207be4030 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3.0","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 3.0 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.261 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.212 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.178 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.145 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.97 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.40 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.5 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2-rc4 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"68469","cve":"CVE-2026-68469","epss":"0.002120000","percentile":"0.117240000","score_date":"2026-08-15","updated_at":"2026-08-16 00:00:33"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/net/wireless/marvell/mwifiex/join.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"2ed36b2586f16c480ed58de303af704c2235e16d","status":"affected","version":"5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e","versionType":"git"},{"lessThan":"5796eabe435d83544b6fe39851ce47ca68fdb778","status":"affected","version":"5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e","versionType":"git"},{"lessThan":"31a2c409f8f58d20f0f6391c151421155768ed77","status":"affected","version":"5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e","versionType":"git"},{"lessThan":"deb5f0ae384f1cf41fccaf6375266db2f2911b2b","status":"affected","version":"5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e","versionType":"git"},{"lessThan":"1bc55db2d34756bd53e4460dbb699619ee13cd7f","status":"affected","version":"5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e","versionType":"git"},{"lessThan":"a59cfa165aee3e29d06145041c0ebe46a51de604","status":"affected","version":"5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e","versionType":"git"},{"lessThan":"6126e12bf8c87badeab41a164c9689ac88e5c160","status":"affected","version":"5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e","versionType":"git"},{"lessThan":"d78a407bad6f500884a8606aea1a5a9207be4030","status":"affected","version":"5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/net/wireless/marvell/mwifiex/join.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"3.0"},{"lessThan":"3.0","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.261","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.212","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.178","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.145","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.97","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.40","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2-rc4","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.261","versionStartIncluding":"3.0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.212","versionStartIncluding":"3.0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.178","versionStartIncluding":"3.0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.145","versionStartIncluding":"3.0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.97","versionStartIncluding":"3.0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.40","versionStartIncluding":"3.0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.5","versionStartIncluding":"3.0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2-rc4","versionStartIncluding":"3.0","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: fix permanently busy scans after multiple roam iterations\n\nIn order for the firmware to sleep, the driver has to confirm a\npreviously received sleep request. The normal sequence of evets goes\nlike this:\nEVENT_SLEEP -> adapter->ps_state = PS_STATE_PRE_SLEEP -> sleep-confirm\n-> SLEEP -> EVENT_AWAKE -> AWAKE.\nBefore sending the sleep-confirm command, the driver must make sure\nthere are no commands either running or waiting to be completed.\n\nmwifiex_ret_802_11_associate() unconditionally sets\nps_state = PS_STATE_AWAKE when it processes the association command\nresponse, outside of the normal powersave management flow. If\nEVENT_SLEEP arrives while the association command is in flight,\nps_state is PRE_SLEEP when the association command response is parsed,\nand the forced AWAKE overwrites it. The deferred sleep-confirm is\nnever sent.\n\nA subsequent scan_start command is correctly acknowledged, but the\nfirmware doesn't generate scan_result events. The scan request never\nfinishes, and additional requests from userspace fail with -EBUSY.\n\nAfter testing on both IW412 and W8997, I could only trigger the bug on\nthe IW412 and observed the firmwares behave differently. On the IW412\nthe firmware still sends EVENT_SLEEP while the authentication /\nassociation process is ongoing. A W8997 under the same\nconditions seems to suppress power-save for the duration of the\nassociation, so PRE_SLEEP never coincided with the association response\neven after extended periods of testing using the loops\ndescribed below (>12hours).\n\nOn the IW412, the delay between commands that triggers an EVENT_SLEEP\nwas empirically determined to be ~20ms. This delay can naturally occur\nwhen the driver is outputting debugging information\n(debug_mask = 0x00000037), in which situation the busy scans issue is\nrepeatable while running \"test 1)\" as described below. If the delay\nbetween commands is less than ~20ms, the firmware stays awake and\nthe issue was not reproducible running the same test.\n\nThe host_mlme=false path also behaves differently. In this case, the\nentire authentication / association transaction is executed by one\ncommand (HostCmd_CMD_802_11_ASSOCIATE), and the firmware doesn't emit\nEVENT_SLEEP while the command is running.\n\nRemove the assignment so the ps_state is only manipulated in the paths\nthat are related to powersave event handling and on the main workqueue\nfor correct sleep confirmation.\n\nThe following loop tests were performed (with debugging output enabled):\n1) force roaming between two AP's, one 5GHz and one 2.4GHz, same\nSSID. Use wpa_cli to trigger the roaming behavior, sleep 2s\nbetween iterations.\n2) force a disconnection to AP 1 and a connection to AP 2, test\nscan. Use wpa_cli to trigger the connection changes, sleep 2s\nbetween iterations.\n\nEach test ran in each device for at least 3 hours."}],"providerMetadata":{"dateUpdated":"2026-08-15T05:51:27.429Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/2ed36b2586f16c480ed58de303af704c2235e16d"},{"url":"https://git.kernel.org/stable/c/5796eabe435d83544b6fe39851ce47ca68fdb778"},{"url":"https://git.kernel.org/stable/c/31a2c409f8f58d20f0f6391c151421155768ed77"},{"url":"https://git.kernel.org/stable/c/deb5f0ae384f1cf41fccaf6375266db2f2911b2b"},{"url":"https://git.kernel.org/stable/c/1bc55db2d34756bd53e4460dbb699619ee13cd7f"},{"url":"https://git.kernel.org/stable/c/a59cfa165aee3e29d06145041c0ebe46a51de604"},{"url":"https://git.kernel.org/stable/c/6126e12bf8c87badeab41a164c9689ac88e5c160"},{"url":"https://git.kernel.org/stable/c/d78a407bad6f500884a8606aea1a5a9207be4030"}],"title":"wifi: mwifiex: fix permanently busy scans after multiple roam iterations","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-68469","datePublished":"2026-08-15T05:51:27.429Z","dateReserved":"2026-07-30T09:28:09.396Z","dateUpdated":"2026-08-15T05:51:27.429Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-15 06:19:57","lastModifiedDate":"2026-08-15 06:19:57","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"68469","Ordinal":"1","Title":"wifi: mwifiex: fix permanently busy scans after multiple roam it","CVE":"CVE-2026-68469","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"68469","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: fix permanently busy scans after multiple roam iterations\n\nIn order for the firmware to sleep, the driver has to confirm a\npreviously received sleep request. The normal sequence of evets goes\nlike this:\nEVENT_SLEEP -> adapter->ps_state = PS_STATE_PRE_SLEEP -> sleep-confirm\n-> SLEEP -> EVENT_AWAKE -> AWAKE.\nBefore sending the sleep-confirm command, the driver must make sure\nthere are no commands either running or waiting to be completed.\n\nmwifiex_ret_802_11_associate() unconditionally sets\nps_state = PS_STATE_AWAKE when it processes the association command\nresponse, outside of the normal powersave management flow. If\nEVENT_SLEEP arrives while the association command is in flight,\nps_state is PRE_SLEEP when the association command response is parsed,\nand the forced AWAKE overwrites it. The deferred sleep-confirm is\nnever sent.\n\nA subsequent scan_start command is correctly acknowledged, but the\nfirmware doesn't generate scan_result events. The scan request never\nfinishes, and additional requests from userspace fail with -EBUSY.\n\nAfter testing on both IW412 and W8997, I could only trigger the bug on\nthe IW412 and observed the firmwares behave differently. On the IW412\nthe firmware still sends EVENT_SLEEP while the authentication /\nassociation process is ongoing. A W8997 under the same\nconditions seems to suppress power-save for the duration of the\nassociation, so PRE_SLEEP never coincided with the association response\neven after extended periods of testing using the loops\ndescribed below (>12hours).\n\nOn the IW412, the delay between commands that triggers an EVENT_SLEEP\nwas empirically determined to be ~20ms. This delay can naturally occur\nwhen the driver is outputting debugging information\n(debug_mask = 0x00000037), in which situation the busy scans issue is\nrepeatable while running \"test 1)\" as described below. If the delay\nbetween commands is less than ~20ms, the firmware stays awake and\nthe issue was not reproducible running the same test.\n\nThe host_mlme=false path also behaves differently. In this case, the\nentire authentication / association transaction is executed by one\ncommand (HostCmd_CMD_802_11_ASSOCIATE), and the firmware doesn't emit\nEVENT_SLEEP while the command is running.\n\nRemove the assignment so the ps_state is only manipulated in the paths\nthat are related to powersave event handling and on the main workqueue\nfor correct sleep confirmation.\n\nThe following loop tests were performed (with debugging output enabled):\n1) force roaming between two AP's, one 5GHz and one 2.4GHz, same\nSSID. Use wpa_cli to trigger the roaming behavior, sleep 2s\nbetween iterations.\n2) force a disconnection to AP 1 and a connection to AP 2, test\nscan. Use wpa_cli to trigger the connection changes, sleep 2s\nbetween iterations.\n\nEach test ran in each device for at least 3 hours.","Type":"Description","Title":"wifi: mwifiex: fix permanently busy scans after multiple roam it"}]}}}