CVE-2026-68404: wifi: cfg80211: use wiphy work for socket owner autodisconnect
Greg Kroah-Hartman <[email protected]>
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026081049-CVE-2026-68404-e1ac@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: use wiphy work for socket owner autodisconnect nl80211_netlink_notify() walks the cfg80211 wireless device list when a NETLINK_GENERIC socket is released. If the socket owns a connection, the notifier queues the embedded wdev->disconnect_wk work item. That work is a plain work_struct today. NETDEV_GOING_DOWN cancels it, but a NETLINK_URELEASE notifier that already observed conn_owner_nlportid can queue it after that cancel returns. _cfg80211_unregister_wdev() then removes the wdev from the list and waits for RCU readers, but synchronize_net() does not drain work queued by such a reader. Make the autodisconnect work a wiphy_work instead. The callback already needs the wiphy mutex, and wiphy_work runs under that mutex. This lets teardown cancel pending autodisconnect work while holding the mutex, without a cancel_work_sync() vs. worker locking concern. Also cancel the wiphy work after list_del_rcu() and synchronize_net(). Any NETLINK_URELEASE notifier that had already reached the wdev list has then either queued the work and it is removed, or can no longer find the wdev. The Linux kernel CVE team has assigned CVE-2026-68404 to this issue. Affected and fixed versions =========================== Issue introduced in 4.11 with commit bd2522b168847106c1885f0319a2833bdf88bf9a and fixed in 7.1.6 with commit 6d6123fef5a4af175cc6b6b12a03dd0f3c240b79 Issue introduced in 4.11 with commit bd2522b168847106c1885f0319a2833bdf88bf9a and fixed in 7.2-rc4 with commit 0c2ed186bbe14304415476d6707b747dddcd8583 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-68404 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: include/net/cfg80211.h net/wireless/core.c net/wireless/core.h net/wireless/nl80211.c net/wireless/sme.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/6d6123fef5a4af175cc6b6b12a03dd0f3c240b79 https://git.kernel.org/stable/c/0c2ed186bbe14304415476d6707b747dddcd8583