CVE-2026-98192: wifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown
In the Linux kernel, the following vulnerability has been resolved:
wifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown
wcn36xxdxedeinit() tears down the TX ack timer with timerdelete(), which only dequeues the timer and does not wait for a callback that is already executing; the preceding freeirq() calls synchronize the interrupt handlers only. The callback, wcn36xxdxetxtimer(), can therefore be running past the teardown and use the wcn freed along with the ieee80211hw in wcn36xxremove(): it takes wcn->dxelock, reads wcn->txackskb and passes wcn->hw to ieee80211txstatusirqsafe().
Fix this by using timershutdownsync(), which waits for a running callback and also prevents the timer from being rearmed again. The timer is set up again by wcn36xxdxeinit() on the next start, so the start/stop cycle is unaffected.
This issue was found by an in-house static analysis tool.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
In the Linux kernel wcn36xx driver, replace the TX ack timer teardown call timer_delete() in wcn36xx_dxe_deinit() with timer_shutdown_sync(), so teardown waits for any running wcn36xx_dxe_tx_timer() callback to finish.