Executive brief
A vulnerability was identified in the Linux kernel's Qualcomm ath11k Wi-Fi driver. The issue occurs when the system attempts to set Wi-Fi bitrate masks, potentially causing the system to crash or become unstable due to an invalid execution context. This could allow a local user with basic privileges to disrupt system operations or potentially gain unauthorized access to system resources.
Technical details
The vulnerability is a 'sleeping-in-atomic' bug within the ath11k Wi-Fi driver, specifically in the ath11k_mac_op_set_bitrate_mask() function. The root cause is the use of ath11k_mac_disable_peer_fixed_rate() as an iterator for ieee80211_iterate_stations_atomic(). Because the iterator function may sleep (via ath11k_wmi_cmd_send), it violates the requirements of the atomic iteration context, leading to a kernel panic or 'BUG: sleeping function called from invalid context'. An attacker with local access could trigger this condition to cause a Denial of Service (DoS) or potentially exploit the resulting unstable state for further privilege escalation. The fix involves switching to the mutex-protected iterator ieee80211_iterate_stations_mtx().
Affected products
- Linux Linux Kernel 5.6 to 6.12.41, 6.13 to 6.15.9, 6.16 to 6.16.0
Timeline
- 2025-09-07: disclosed
- 2025-09-07: advisory
- 2025-08-15: patched: Patched in stable branches 6.12.42, 6.15.10, 6.16.1