CVE-2026-68414: wifi: cfg80211: cancel sched scan results work on unregister

Greg Kroah-Hartman <[email protected]>
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026081051-CVE-2026-68414-1451@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

wifi: cfg80211: cancel sched scan results work on unregister

cfg80211_sched_scan_results() can queue rdev->sched_scan_res_wk from a
driver result notification while a scheduled scan request is present. The
work callback recovers the containing cfg80211_registered_device and then
locks the wiphy and walks the scheduled-scan request list.

wiphy_unregister() already makes the wiphy unreachable and drains rdev work
items before cfg80211_dev_free() can release the object, but it does not
drain sched_scan_res_wk. A queued or running result work item can therefore
cross the unregister/free boundary and access freed rdev state.

The buggy scenario involves two paths, with each column showing the order
within that path:

scheduled-scan result path:        unregister/free path:
1. cfg80211_sched_scan_results()   1. interface teardown stops and
   queues rdev->sched_scan_res_wk.    removes the scheduled scan request.
2. cfg80211_wq starts the work     2. wiphy_unregister() drains other
   item and recovers rdev.            rdev work items.
3. The worker locks rdev->wiphy    3. cfg80211_dev_free() destroys and
   and walks rdev state.              frees rdev.

Cancel sched_scan_res_wk in wiphy_unregister() alongside the other rdev
work items. cancel_work_sync() removes a pending result notification and
waits for an already running callback, so cfg80211_dev_free() cannot free
rdev while this work item is still active.

Validation reproduced this kernel report:
BUG: KASAN: use-after-free in cfg80211_sched_scan_results_wk+0x4a6/0x530
Workqueue: cfg80211 cfg80211_sched_scan_results_wk [cfg80211]
Read of size 8
Call trace:
  dump_stack_lvl+0x66/0xa0
  print_report+0xce/0x630
  cfg80211_sched_scan_results_wk+0x4a6/0x530
  srso_alias_return_thunk+0x5/0xfbef5
  __virt_addr_valid+0x224/0x430
  kasan_report+0xac/0xe0
  lockdep_hardirqs_on_prepare+0xea/0x1a0
  process_one_work+0x8d0/0x18f0 (kernel/workqueue.c:3212)
  lock_is_held_type+0x8f/0x100
  worker_thread+0x5ad/0xfd0
  __kthread_parkme+0xc6/0x200
  kthread+0x31e/0x410
  trace_hardirqs_on+0x1a/0x170
  ret_from_fork+0x576/0x810
  __switch_to+0x57e/0xe20
  __switch_to_asm+0x33/0x70
  ret_from_fork_asm+0x1a/0x30

The Linux kernel CVE team has assigned CVE-2026-68414 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 3.0 with commit 807f8a8c300435d5483e8d78df9dcdbc27333166 and fixed in 6.6.148 with commit 3368457b4871ae8f0f88d19c9a3e6270e850ede6
	Issue introduced in 3.0 with commit 807f8a8c300435d5483e8d78df9dcdbc27333166 and fixed in 6.12.101 with commit 308ffdf575560d7e7b8b21f1e3ca6276630f73bf
	Issue introduced in 3.0 with commit 807f8a8c300435d5483e8d78df9dcdbc27333166 and fixed in 6.18.42 with commit 9293574ac208d18c11073538851fb69355beb3b5
	Issue introduced in 3.0 with commit 807f8a8c300435d5483e8d78df9dcdbc27333166 and fixed in 7.1.6 with commit b119c70b24776c8ab2a2c0515397b3b0ad4e66cd
	Issue introduced in 3.0 with commit 807f8a8c300435d5483e8d78df9dcdbc27333166 and fixed in 7.2-rc4 with commit edf0730be33696a1bd142792830d392129e495cc

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-68414
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	net/wireless/core.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/3368457b4871ae8f0f88d19c9a3e6270e850ede6
	https://git.kernel.org/stable/c/308ffdf575560d7e7b8b21f1e3ca6276630f73bf
	https://git.kernel.org/stable/c/9293574ac208d18c11073538851fb69355beb3b5
	https://git.kernel.org/stable/c/b119c70b24776c8ab2a2c0515397b3b0ad4e66cd
	https://git.kernel.org/stable/c/edf0730be33696a1bd142792830d392129e495cc
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.