Executive brief
A vulnerability in the Linux kernel's Wi-Fi stack could allow a local attacker to cause a system deadlock, leading to a complete service outage (denial of service). The issue occurs in the mac80211 framework, which manages wireless networking operations. An exploit would result in the system becoming unresponsive, requiring a hard reboot and potentially disrupting network connectivity and business operations.
Technical details
A deadlock exists in the mac80211 subsystem within the ieee80211_sta_ps_deliver_wakeup() function. The root cause is the use of spin_lock() instead of spin_lock_bh() when acquiring sta->ps_lock. Because ieee80211_tx_h_unicast_ps_buf() can be called from a softirq context on the same CPU, it may attempt to acquire the same lock already held by the wakeup function, resulting in a circular dependency and an RCU stall. An attacker with local access could trigger this condition to cause a kernel panic or system hang. The issue has been resolved by switching to bottom-half-safe locking primitives (spin_lock_bh).
Affected products
- Linux Linux Kernel 3.14 to 4.19.317, 5.4.279, 5.10.221, 5.15.162, 6.1.96, 6.6.36, 6.9.7
Timeline
- 2024-05-29: patched: Initial fix developed and signed off by maintainers.
- 2024-07-12: advisory: CVE-2024-40912 published.
References
- https://git.kernel.org/stable/c/28ba44d680a30c51cf485a2f5a3b680e66ed3932
- https://git.kernel.org/stable/c/44c06bbde6443de206b30f513100b5670b23fc5e
- https://git.kernel.org/stable/c/456bbb8a31e425177dc0e8d4f98728a560c20e81
- https://git.kernel.org/stable/c/47d176755d5c0baf284eff039560f8c1ba0ea485
- https://git.kernel.org/stable/c/9c49b58b9a2bed707e7638576e54c4bccd97b9eb
- https://git.kernel.org/stable/c/d90bdff79f8e40adf889b5408bfcf521528b169f
- https://git.kernel.org/stable/c/e51637e0c66a6f72d134d9f95daa47ea62b43c7e