CVE-2026-98307: wifi: ath11k: cleanup arsta in ath11k_mac_peer_cleanup_all()
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: cleanup arsta in ath11kmacpeercleanupall()
When mac80211 removes a sta, it calls .stastate() which in turn calls ath11kmacstationremove(). In that function we clean up both peers & arsta related resources.
But when the firmware crashes, ath11k calls ieee80211restarthw(), which assumes that all driver related resources are cleaned up beforehand. This cleanup is supposedly done by ath11kmacpeercleanupall() but does not in fact free arsta->rxstats / txstats.
Extract the arsta cleanup from ath11kmacstationremove() into a new ath11kmacstationcleanup() and call it from both there and ath11kmacpeercleanupall().
This should handle kmemleaks reports like: unreferenced object 0xffffff801ae66400 (size 1024): comm "hostapd", pid 1306, jiffies 4295011565 hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace (crc d61c08ec): kmemleakalloc+0x3c/0x50 kmalloccachenoprof+0x2b0/0x3e0 ath11kmacopstastate+0x1dc/0xb10 drvstastate+0xac/0x6f8 stainfoinsertrcu+0x314/0x5e0 stainfoinsert+0x14/0x38 ieee80211addstation+0x10c/0x1a0 nl80211newstation+0x3e8/0x680 genlfamilyrcvmsgdoit+0xc0/0x120 genlrcvmsg+0x1b4/0x258 netlinkrcvskb+0x4c/0x108 genlrcv+0x38/0x60 netlinkunicast+0x190/0x278 netlinksendmsg+0x15c/0x370 syssendmsg+0x120/0x290 syssendmsg+0x70/0xa0
Tested-on: QCN9074 hw1.0 PCI WLAN.HK.2.9.0.1-01977-QCAHKSWPLSILICONZ-1
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Systems using the Linux kernel ath11k Wi-Fi driver are implicated. The affected cleanup path is exercised for stations managed through mac80211.
What event triggers the resource leak?
The leak occurs when ath11k firmware crashes and ath11k invokes ieee80211_restart_hw(). During the pre-restart peer cleanup, arsta receive and transmit statistics allocations were not freed.
How can administrators identify a potentially affected system?
Kernel memory leak detection may report unreferenced 1024-byte objects allocated through ath11k station-state handling, with traces involving ath11k_mac_op_sta_state and station insertion. The example report was observed while hostapd was running.