Executive brief
A vulnerability in the Linux kernel's Qualcomm Wi-Fi driver (ath12k) can cause the wireless hardware firmware to crash. This occurs when the system attempts to use 'Wake on Wireless' (WoW) power-saving features on multiple network links simultaneously. An exploit or trigger of this condition would result in a loss of Wi-Fi connectivity and potential system instability for devices using affected Qualcomm WCN7850 hardware.
Technical details
A vulnerability in the Linux kernel ath12k driver's WoW (Wake on Wireless) implementation leads to a firmware crash on Qualcomm WCN7850 hardware. The root cause is the driver enabling WoW offloads on both primary and secondary links in a multi-link operation (MLO) connection, which the WCN7850 firmware cannot handle. An attacker on the local wireless network could potentially trigger this crash by interacting with the device's multi-link power management states. The fix restricts WoW offloads, including ARP/NS and GTK rekey offloading, to the primary link only. Patches have been merged into the Linux stable tree.
Affected products
- Linux Linux Kernel ath12k driver; WCN7850 hw2.0 firmware
Timeline
- 2025-11-03: other: Initial patch authored
- 2026-01-15: patched: Patch committed to mainline kernel
- 2026-06-03: advisory: CVE-2026-46271 published