Executive brief
A vulnerability in the Linux kernel's Qualcomm ath11k Wi-Fi driver can cause a system crash (kernel panic) during power management operations like resuming from sleep. This occurs when the driver fails to properly reset its internal state after a firmware crash, leading it to access invalid memory locations. A successful exploit could result in a complete system shutdown or denial of service for devices using these Wi-Fi chips.
Technical details
A vulnerability exists in the Linux kernel ath11k Wi-Fi driver due to missing initialization of resources in the ath11k_hal_srng_deinit() function. When the driver attempts to reconfigure after a firmware crash, it destroys SRNG (Static Ring) lists but fails to clear the 'initialized' flag. A subsequent call to ath11k_hal_dump_srng_stats() relies on this stale flag, leading to a supervisor read access page fault (NULL pointer dereference or use-after-free style access) and a kernel panic. The issue is triggered during crash recovery or system resume cycles. Patches have been released for various stable kernel branches to ensure the flag is cleared during de-initialization.
Affected products
- Linux Linux Kernel ath11k driver
Timeline
- 2025-06-12: patched: Initial patch submitted by Sergey Senozhatsky
- 2025-08-19: advisory: CVE-2025-38601 published
References
- https://git.kernel.org/stable/c/0ebb5fe494501c19f31270008b26ab95201af6fd
- https://git.kernel.org/stable/c/16872194c80f2724472fc207991712895ac8a230
- https://git.kernel.org/stable/c/3a6daae987a829534636fd85ed6f84d5f0ad7fa4
- https://git.kernel.org/stable/c/5bf201c55fdf303e79005038648dfa1e8af48f54
- https://git.kernel.org/stable/c/72a48be1f53942793f3bc68a37fad1f38b53b082
- https://git.kernel.org/stable/c/916ac18d526a26f6072866b1a97622cf1351ef1c
- https://git.kernel.org/stable/c/a5b46aa7cf5f05c213316a018e49a8e086efd98e