CVE-2025-38601: wifi: ath11k: clear initialized flag for deinit-ed srng lists
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: clear initialized flag for deinit-ed srng lists
In a number of cases we see kernel panics on resume due to ath11k kernel page fault, which happens under the following circumstances:
1) First ath11khaldumpsrngstats() call
Last interrupt received for each group: ath11kpci 0000:01:00.0: groupid 0 22511ms before ath11kpci 0000:01:00.0: groupid 1 14440788ms before [..] ath11kpci 0000:01:00.0: failed to receive control response completion, polling.. ath11kpci 0000:01:00.0: Service connect timeout ath11kpci 0000:01:00.0: failed to connect to HTT: -110 ath11kpci 0000:01:00.0: failed to start core: -110 ath11kpci 0000:01:00.0: firmware crashed: MHICBEERDDM ath11kpci 0000:01:00.0: already resetting count 2 ath11kpci 0000:01:00.0: failed to wait wlan mode request (mode 4): -110 ath11kpci 0000:01:00.0: qmi failed to send wlan mode off: -110 ath11kpci 0000:01:00.0: failed to reconfigure driver on crash recovery [..]
2) At this point reconfiguration fails (we have 2 resets) and ath11kcorereconfigureoncrash() calls ath11khalsrngdeinit() which destroys srng lists. However, it does not reset per-list ->initialized flag.
3) Second ath11khaldumpsrngstats() call sees stale ->initialized flag and attempts to dump srng stats:
Last interrupt received for each group: ath11kpci 0000:01:00.0: groupid 0 66785ms before ath11kpci 0000:01:00.0: groupid 1 14485062ms before ath11kpci 0000:01:00.0: groupid 2 14485062ms before ath11kpci 0000:01:00.0: groupid 3 14485062ms before ath11kpci 0000:01:00.0: groupid 4 14780845ms before ath11kpci 0000:01:00.0: groupid 5 14780845ms before ath11kpci 0000:01:00.0: groupid 6 14485062ms before ath11kpci 0000:01:00.0: groupid 7 66814ms before ath11kpci 0000:01:00.0: groupid 8 68997ms before ath11kpci 0000:01:00.0: groupid 9 67588ms before ath11kpci 0000:01:00.0: groupid 10 69511ms before BUG: unable to handle page fault for address: ffffa007404eb010 #PF: supervisor read access in kernel mode #PF: errorcode(0x0000) - not-present page PGD 100000067 P4D 100000067 PUD 10022d067 PMD 100b01067 PTE 0 Oops: 0000 [#1] PREEMPT SMP NOPTI RIP: 0010:ath11khaldumpsrngstats+0x2b4/0x3b0 [ath11k] Call Trace: <TASK> ? diebody+0xae/0xb0 ? pagefaultoops+0x381/0x3e0 ? excpagefault+0x69/0xa0 ? asmexcpagefault+0x22/0x30 ? ath11khaldumpsrngstats+0x2b4/0x3b0 [ath11k (HASH:6cea 4)] ath11kqmidrivereventwork+0xbd/0x1050 [ath11k (HASH:6cea 4)] workerthread+0x389/0x930 kthread+0x149/0x170
Clear per-list ->initialized flag in ath11khalsrngdeinit().
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
In ath11k_hal_srng_deinit(), Clear per-list ->initialized flag for deinit-ed SRNG lists so it is reset correctly (the issue is that it clears the global/outer flag but does not reset per-list, leaving stale ->initialized and causing ath11k_hal_dump_srng_stats() to page-fault on resume/crash recovery).
ath11k (Linux kernel driver) per-list initialized flag in ath11k_hal_srng_deinit() = cleared
Event History
Frequently Asked Questions
What is the severity of CVE-2025-38601?
The severity of CVE-2025-38601 is classified as moderate due to its potential impact on system stability.
How do I fix CVE-2025-38601?
To fix CVE-2025-38601, update your Linux kernel to the latest version where this vulnerability has been patched.
What systems are affected by CVE-2025-38601?
CVE-2025-38601 affects the Linux Kernel, particularly systems utilizing the ath11k driver.
What are the symptoms of CVE-2025-38601 exploitation?
Exploitation of CVE-2025-38601 may lead to kernel panics and system crashes upon resume.
Is CVE-2025-38601 a persistent threat?
CVE-2025-38601 is not a persistent threat as it leads to a crash rather than unauthorized access.