Executive brief
The Linux kernel's WiFi driver for Qualcomm ath12k chipsets fails to properly acquire a required lock when processing packet errors in the WBM (buffer manager) subsystem. This can lead to race conditions and memory corruption when the driver attempts to find peer devices, potentially causing system crashes or enabling local privilege escalation on affected systems running vulnerable kernel versions.
Technical details
The vulnerability is a missing lock acquisition in the ath12k WiFi driver's WBM error handling path. The function ath12k_peer_find_by_id() requires callers to hold the ab->base_lock spinlock, but the WBM error processing code path (ath12k_dp_rx_process_wbm_err) calls this function without acquiring the lock first. This violation triggers a kernel lockdep_assert warning and creates a race condition where concurrent access to peer data structures can cause memory safety violations. The attack vector is local (triggered through network packet processing), and the fix involves properly acquiring and releasing the spinlock around the vulnerable code section.
Affected products
- Linux Linux Kernel Affected versions not precisely specified in advisory; QCN9274 hw2.0 testing noted
Timeline
- 2025-12-08: disclosed
- patched: Fix applied to kernel source to handle spinlock in WBM error path